CVE Feed

    Dashboard / CVE / CVE-2019-3800

    CVE-2019-3800

    CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

    Published:Aug 5, 2019
    Last Modified:Nov 21, 2024
    EPS:Aug 5, 2019
    EPSS Score:0.00205
    CVSS Score:6.3

    Affected Products

    Vendor
    Anynines
    Product
    Elasticsearch
    Vendor
    Anynines
    Product
    Logme
    Vendor
    Anynines
    Product
    Mongodb
    Vendor
    Anynines
    Product
    Mysql
    Vendor
    Anynines
    Product
    Postgresql
    Vendor
    Anynines
    Product
    Rabbitmq
    Vendor
    Anynines
    Product
    Redis
    Vendor
    Apigee
    Product
    Edge Service Broker
    Vendor
    Appdynamics
    Product
    Application Analytics
    Vendor
    Appdynamics
    Product
    Application Performance Monitoring
    Vendor
    Appdynamics
    Product
    Platform Montioring
    Vendor
    Bluemedora
    Product
    Nozzle
    Vendor
    Contrastsecurity
    Product
    Service Broker
    Vendor
    Cyberark
    Product
    Conjur Service Broker
    Vendor
    Datadoghq
    Product
    Application Monitoring
    Vendor
    Datastax
    Product
    Enterprise Service Broker
    Vendor
    Dynatrace
    Product
    Service Broker
    Vendor
    Forgerock
    Product
    Service Broker
    Vendor
    Google
    Product
    Google Cloud Platform Service Broker
    Vendor
    Ibm
    Product
    Websphere Liberty
    Vendor
    Microsoft
    Product
    Azure Log Analytics Nozzle
    Vendor
    Microsoft
    Product
    Azure Service Broker
    Vendor
    Newrelic
    Product
    Dotnet Extension Buildpack
    Vendor
    Newrelic
    Product
    Nozzle
    Vendor
    Newrelic
    Product
    Service Broker
    Vendor
    Pagerduty
    Product
    Service Broker
    Vendor
    Pivotal
    Product
    Application Service
    Vendor
    Pivotal
    Product
    Cloud Foundry Autoscaling Release
    Vendor
    Pivotal
    Product
    Cloud Foundry Command Line Interface
    Vendor
    Pivotal
    Product
    Cloud Foundry Command Line Interface Release
    Vendor
    Pivotal
    Product
    Cloud Foundry Deployment
    Vendor
    Pivotal
    Product
    Cloud Foundry Deployment Concourse Tasks
    Vendor
    Pivotal
    Product
    Cloud Foundry Event Alerts
    Vendor
    Pivotal
    Product
    Cloud Foundry Healthwatch
    Vendor
    Pivotal
    Product
    Cloud Foundry Log Cache Release
    Vendor
    Pivotal
    Product
    Cloud Foundry Networking Release
    Vendor
    Pivotal
    Product
    Cloud Foundry Notifications
    Vendor
    Pivotal
    Product
    Cloud Foundry Routing Release
    Vendor
    Pivotal
    Product
    Cloud Foundry Smoke Test
    Vendor
    Pivotal
    Product
    Credhub Service Broker For Pcf
    Vendor
    Pivotal
    Product
    Metric Registrar Release
    Vendor
    Pivotal
    Product
    On Demand Service Broker
    Vendor
    Pivotal
    Product
    Pivotal Cloud Foundry Service Broker
    Vendor
    Pivotal
    Product
    Single Sign-on
    Vendor
    Riverbed
    Product
    Steelcentral Appinternals
    Vendor
    Samba
    Product
    Volume Service
    Vendor
    Signalsciences
    Product
    Service Broker
    Vendor
    Snyk
    Product
    Service Broker
    Vendor
    Solace
    Product
    Pubsub\+
    Vendor
    Splunk
    Product
    Nozzle
    Vendor
    Sumologic
    Product
    Nozzle
    Vendor
    Synopsys
    Product
    Seeker Iast Service Broker
    Vendor
    Tibco
    Product
    Businessworks Buildpack
    Vendor
    Wavefront
    Product
    Wavefront By Vmware Nozzle
    Vendor
    Yugabyte
    Product
    Db Enterprise

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High