CVE-2019-3800
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
Published:Aug 5, 2019
Last Modified:Nov 21, 2024
EPS:Aug 5, 2019
EPSS Score:0.00205
CVSS Score:6.3
Affected Products
Vendor
Product
Action
Vendor
Anynines
Product
Elasticsearch
Anynines
Elasticsearch
Vendor
Anynines
Product
Logme
Anynines
Logme
Vendor
Anynines
Product
Mongodb
Anynines
Mongodb
Vendor
Anynines
Product
Mysql
Anynines
Mysql
Vendor
Anynines
Product
Postgresql
Anynines
Postgresql
Vendor
Anynines
Product
Rabbitmq
Anynines
Rabbitmq
Vendor
Anynines
Product
Redis
Anynines
Redis
Vendor
Apigee
Product
Edge Service Broker
Apigee
Edge Service Broker
Vendor
Appdynamics
Product
Application Analytics
Appdynamics
Application Analytics
Vendor
Appdynamics
Product
Application Performance Monitoring
Appdynamics
Application Performance Monitoring
Vendor
Appdynamics
Product
Platform Montioring
Appdynamics
Platform Montioring
Vendor
Bluemedora
Product
Nozzle
Bluemedora
Nozzle
Vendor
Contrastsecurity
Product
Service Broker
Contrastsecurity
Service Broker
Vendor
Cyberark
Product
Conjur Service Broker
Cyberark
Conjur Service Broker
Vendor
Datadoghq
Product
Application Monitoring
Datadoghq
Application Monitoring
Vendor
Datastax
Product
Enterprise Service Broker
Datastax
Enterprise Service Broker
Vendor
Dynatrace
Product
Service Broker
Dynatrace
Service Broker
Vendor
Forgerock
Product
Service Broker
Forgerock
Service Broker
Vendor
Google
Product
Google Cloud Platform Service Broker
Google
Google Cloud Platform Service Broker
Vendor
Ibm
Product
Websphere Liberty
Ibm
Websphere Liberty
Vendor
Microsoft
Product
Azure Log Analytics Nozzle
Microsoft
Azure Log Analytics Nozzle
Vendor
Microsoft
Product
Azure Service Broker
Microsoft
Azure Service Broker
Vendor
Newrelic
Product
Dotnet Extension Buildpack
Newrelic
Dotnet Extension Buildpack
Vendor
Newrelic
Product
Nozzle
Newrelic
Nozzle
Vendor
Newrelic
Product
Service Broker
Newrelic
Service Broker
Vendor
Pagerduty
Product
Service Broker
Pagerduty
Service Broker
Vendor
Pivotal
Product
Application Service
Pivotal
Application Service
Vendor
Pivotal
Product
Cloud Foundry Autoscaling Release
Pivotal
Cloud Foundry Autoscaling Release
Vendor
Pivotal
Product
Cloud Foundry Command Line Interface
Pivotal
Cloud Foundry Command Line Interface
Vendor
Pivotal
Product
Cloud Foundry Command Line Interface Release
Pivotal
Cloud Foundry Command Line Interface Release
Vendor
Pivotal
Product
Cloud Foundry Deployment
Pivotal
Cloud Foundry Deployment
Vendor
Pivotal
Product
Cloud Foundry Deployment Concourse Tasks
Pivotal
Cloud Foundry Deployment Concourse Tasks
Vendor
Pivotal
Product
Cloud Foundry Event Alerts
Pivotal
Cloud Foundry Event Alerts
Vendor
Pivotal
Product
Cloud Foundry Healthwatch
Pivotal
Cloud Foundry Healthwatch
Vendor
Pivotal
Product
Cloud Foundry Log Cache Release
Pivotal
Cloud Foundry Log Cache Release
Vendor
Pivotal
Product
Cloud Foundry Networking Release
Pivotal
Cloud Foundry Networking Release
Vendor
Pivotal
Product
Cloud Foundry Notifications
Pivotal
Cloud Foundry Notifications
Vendor
Pivotal
Product
Cloud Foundry Routing Release
Pivotal
Cloud Foundry Routing Release
Vendor
Pivotal
Product
Cloud Foundry Smoke Test
Pivotal
Cloud Foundry Smoke Test
Vendor
Pivotal
Product
Credhub Service Broker For Pcf
Pivotal
Credhub Service Broker For Pcf
Vendor
Pivotal
Product
Metric Registrar Release
Pivotal
Metric Registrar Release
Vendor
Pivotal
Product
On Demand Service Broker
Pivotal
On Demand Service Broker
Vendor
Pivotal
Product
Pivotal Cloud Foundry Service Broker
Pivotal
Pivotal Cloud Foundry Service Broker
Vendor
Pivotal
Product
Single Sign-on
Pivotal
Single Sign-on
Vendor
Riverbed
Product
Steelcentral Appinternals
Riverbed
Steelcentral Appinternals
Vendor
Samba
Product
Volume Service
Samba
Volume Service
Vendor
Signalsciences
Product
Service Broker
Signalsciences
Service Broker
Vendor
Snyk
Product
Service Broker
Snyk
Service Broker
Vendor
Solace
Product
Pubsub\+
Solace
Pubsub\+
Vendor
Splunk
Product
Nozzle
Splunk
Nozzle
Vendor
Sumologic
Product
Nozzle
Sumologic
Nozzle
Vendor
Synopsys
Product
Seeker Iast Service Broker
Synopsys
Seeker Iast Service Broker
Vendor
Tibco
Product
Businessworks Buildpack
Tibco
Businessworks Buildpack
Vendor
Wavefront
Product
Wavefront By Vmware Nozzle
Wavefront
Wavefront By Vmware Nozzle
Vendor
Yugabyte
Product
Db Enterprise
Yugabyte
Db Enterprise
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
