ZeroHour

CVE-2019-3800

CVSS 3.0
7.8 high
EPSS
2%p80
Published
()
Modified
Description

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

Vendors
pivotalanyninesapigeeappdynamicsbluemedoracontrastsecuritycyberarkdatadoghqdatastaxdynatraceforgerockgoogle
Products
cloud foundry command line interface, cloud foundry command line interface release, cloud foundry deployment, cloud foundry deployment concourse tasks, cloud foundry log cache release, cloud foundry networking release, cloud foundry notifications, cloud foundry routing release, cloud foundry smoke test, application service, cloud foundry autoscaling release, cloud foundry event alerts
Weakness
CWE-522, CWE-200
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.