7.8

CVE-2019-3800

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

Data is provided by the National Vulnerability Database (NVD)
PivotalCloud Foundry Deployment Version < 10.0.0
PivotalCloud Foundry Routing Release Version < 0.189.0
PivotalCloud Foundry Smoke Test Version < 40.0.113
PivotalApplication Service Version >= 2.3.0 < 2.3.14
PivotalApplication Service Version >= 2.4.0 < 2.4.10
PivotalApplication Service Version >= 2.5.0 < 2.5.6
PivotalCloud Foundry Event Alerts Version < 1.2.8
PivotalCloud Foundry Healthwatch Version >= 1.4.0 < 1.4.7
PivotalCloud Foundry Healthwatch Version >= 1.5.0 < 1.5.4
PivotalOn Demand Service Broker Version < 0.29.0
PivotalPivotal Cloud Foundry Service Broker SwPlatformaws Version < 1.4.13
PivotalSingle Sign-on SwPlatformcloud_foundry Version >= 1.7.0 < 1.7.5
PivotalSingle Sign-on SwPlatformcloud_foundry Version >= 1.8.0 < 1.8.4
PivotalSingle Sign-on SwPlatformcloud_foundry Version >= 1.9.0 < 1.9.1
AnyninesElasticsearch SwPlatformpivotal_cloud_foundry Version < 2.1.2
AnyninesLogme SwPlatformpivotal_cloud_foundry Version < 2.1.2
AnyninesMongodb SwPlatformpivotal_cloud_foundry Version < 2.1.2
AnyninesMysql SwPlatformpivotal_cloud_foundry Version < 2.1.2
AnyninesPostgresql SwPlatformpivotal_cloud_foundry Version < 2.1.2
AnyninesRabbitmq SwPlatformpivotal_cloud_foundry Version < 2.1.2
AnyninesRedis SwPlatformpivotal_cloud_foundry Version < 2.1.2
ApigeeEdge Service Broker SwPlatformpivotal_cloud_foundry Version < 3.1.3
AppdynamicsApplication Analytics SwPlatformpivotal_cloud_foundry Version < 4.7.652
AppdynamicsApplication Performance Monitoring SwPlatformpivotal_cloud_foundry Version < 4.6.64
AppdynamicsPlatform Montioring SwPlatformpivotal_cloud_foundry Version < 4.7.712
BluemedoraNozzle SwPlatformpivotal_cloud_foundry Version < 3.1.1
ContrastsecurityService Broker SwPlatformpivotal_cloud_foundry Version < 2.2.0
CyberarkConjur Service Broker SwPlatformpivotal_cloud_foundry Version < 1.1.1
DatadoghqApplication Monitoring SwPlatformpivotal_cloud_foundry Version < 1.7.0
DatastaxEnterprise Service Broker SwPlatformpivotal_cloud_foundry Version < 1.0.2
DynatraceService Broker SwPlatformpivotal_cloud_foundry Version < 1.4.2
ForgerockService Broker SwPlatformpivotal_cloud_foundry Version < 2.1.2
GoogleGoogle Cloud Platform Service Broker SwPlatformpivotal_cloud_foundry Version < 4.2.3
IbmWebsphere Liberty SwPlatformpivotal_cloud_foundry Version < 3.11.0
MicrosoftAzure Log Analytics Nozzle SwPlatformpivotal_cloud_foundry Version < 1.4.1
MicrosoftAzure Service Broker SwPlatformpivotal_cloud_foundry Version < 1.4.1
NewrelicDotnet Extension Buildpack SwPlatformpivotal_cloud_foundry Version < 1.1.1
NewrelicNozzle SwPlatformpivotal_cloud_foundry Version < 1.1.17
NewrelicService Broker SwPlatformpivotal_cloud_foundry Version < 1.12.64
PagerdutyService Broker SwPlatformpivotal_cloud_foundry Version < 1.2.4
RiverbedSteelcentral Appinternals SwPlatformpivotal_cloud_foundry Version < 10.21.1-bl516
SambaVolume Service SwPlatformpivotal_cloud_foundry Version < 1.1.1
SignalsciencesService Broker SwPlatformpivotal_cloud_foundry Version < 1.1.0
SnykService Broker SwPlatformpivotal_cloud_foundry Version < 1.0.3
SolacePubsub+ SwPlatformpivotal_cloud_foundry Version < 2.3.2
SplunkNozzle SwPlatformpivotal_cloud_foundry Version < 1.1.1
SumologicNozzle SwPlatformpivotal_cloud_foundry Version < 1.0.1
SynopsysSeeker Iast Service Broker SwPlatformpivotal_cloud_foundry Version < 1.2.14
TibcoBusinessworks Buildpack SwEditioncontainer SwPlatformpivotal_cloud_foundry Version < 2.4.4
WavefrontWavefront By Vmware Nozzle SwPlatformpivotal_cloud_foundry Version < 1.0.2
YugabyteDb Enterprise SwPlatformpivotal_cloud_foundry Version < 1.1.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.21% 0.428
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
security_alert@emc.com 6.3 2 3.7
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.