CVE-2019-3800

NONE
Published Aug 5, 20196y ago · Modified Jun 17, 20261w ago
Find Similar
Published Aug 5, 2019 6y ago
Last Modified Jun 17, 2026 1w ago

Description

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

Threat Intelligence

No active exploitation signals — not in CISA KEV and no EPSS score yet.

Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 2

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor Information Exposure
CWE-522

Affected Products 60

VendorProductVersionRange
pivotalcloud_foundry_command_line_interface* <6.45.0
pivotalcloud_foundry_command_line_interface_release* <1.16.0
pivotalcloud_foundry_deployment* <10.0.0
pivotalcloud_foundry_deployment_concourse_tasks* <9.3.0
pivotalcloud_foundry_log_cache_release* <2.3.1
pivotalcloud_foundry_networking_release* <2.23.0
pivotalcloud_foundry_notifications* <58
pivotalcloud_foundry_routing_release* <0.189.0
pivotalcloud_foundry_smoke_test* <40.0.113
pivotalapplication_service*≥2.3.0  –  <2.3.14
pivotalapplication_service*≥2.4.0  –  <2.4.10
pivotalapplication_service*≥2.5.0  –  <2.5.6
pivotalcloud_foundry_autoscaling_release* <219
pivotalcloud_foundry_event_alerts* <1.2.8
pivotalcloud_foundry_healthwatch*≥1.4.0  –  <1.4.7
pivotalcloud_foundry_healthwatch*≥1.5.0  –  <1.5.4
pivotalcredhub_service_broker_for_pcf* <1.3.2
pivotalmetric_registrar_release* <1.2
pivotalon_demand_service_broker* <0.29.0
pivotalpivotal_cloud_foundry_service_broker* <1.4.13
pivotalsingle_sign-on*≥1.7.0  –  <1.7.5
pivotalsingle_sign-on*≥1.8.0  –  <1.8.4
pivotalsingle_sign-on*≥1.9.0  –  <1.9.1
anynineselasticsearch* <2.1.2
anynineslogme* <2.1.2
anyninesmongodb* <2.1.2
anyninesmysql* <2.1.2
anyninespostgresql* <2.1.2
anyninesrabbitmq* <2.1.2
anyninesredis* <2.1.2
apigeeedge_service_broker* <3.1.3
appdynamicsapplication_analytics* <4.7.652
appdynamicsapplication_performance_monitoring* <4.6.64
appdynamicsplatform_montioring* <4.7.712
bluemedoranozzle* <3.1.1
contrastsecurityservice_broker* <2.2.0
cyberarkconjur_service_broker* <1.1.1
datadoghqapplication_monitoring* <1.7.0
datastaxenterprise_service_broker* <1.0.2
dynatraceservice_broker* <1.4.2
forgerockservice_broker* <2.1.2
googlegoogle_cloud_platform_service_broker* <4.2.3
ibmwebsphere_liberty_* <3.11.0
microsoftazure_log_analytics_nozzle* <1.4.1
microsoftazure_service_broker* <1.4.1
newrelicdotnet_extension_buildpack* <1.1.1
newrelicnozzle* <1.1.17
newrelicservice_broker* <1.12.64
pagerdutyservice_broker* <1.2.4
riverbedsteelcentral_appinternals* <10.21.1-bl516
sambavolume_service* <1.1.1
signalsciencesservice_broker* <1.1.0
snykservice_broker* <1.0.3
solacepubsub\+* <2.3.2
splunknozzle* <1.1.1
sumologicnozzle* <1.0.1
synopsysseeker_iast_service_broker* <1.2.14
tibcobusinessworks_buildpack* <2.4.4
wavefrontwavefront_by_vmware_nozzle* <1.0.2
yugabytedb_enterprise* <1.1.8

References 2

  • pivotal.io https://pivotal.io/security/cve-2019-3800
    Vendor Advisory
  • cloudfoundry.org https://www.cloudfoundry.org/blog/cve-2019-3800
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.