VDB

CVE-2019-3800

CVE-2019-3800 PUBLISHED CVSS 6.300000190734863 MEDIUM

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

EPSS 2.09% · 79.8th percentile

Risk Scores

CVSS 3.0
6.300000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
EPSS Score
2.09%
79.8th percentile

Affected Products

VendorProductVersions
pivotalcloud_foundry_smoke_test0
pivotalcloud_foundry_deployment_concourse_tasks0
anynineselasticsearch0
yugabytedb_enterprise0
pivotalon_demand_service_broker0
pivotalsingle_sign-on1.7.0, 1.9.0, 1.8.0
pivotalcredhub_service_broker_for_pcf0
datastaxenterprise_service_broker0
bluemedoranozzle0
tibcobusinessworks_buildpack0
anyninesmysql0
signalsciencesservice_broker0
contrastsecurityservice_broker0
pivotalcloud_foundry_command_line_interface0
anynineslogme0
anyninesmongodb0
pivotalmetric_registrar_release0
pivotalcloud_foundry_autoscaling_release0
appdynamicsapplication_analytics0
anyninesrabbitmq0

…and 37 more

Timeline

  • Aug 5, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›