Description
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
Published: 2019-08-05
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-13427 CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
History

No history.

Subscriptions

Anynines Elasticsearch Logme Mongodb Mysql Postgresql Rabbitmq Redis
Apigee Edge Service Broker
Appdynamics Application Analytics Application Performance Monitoring Platform Montioring
Bluemedora Nozzle
Contrastsecurity Service Broker
Cyberark Conjur Service Broker
Datadoghq Application Monitoring
Datastax Enterprise Service Broker
Dynatrace Service Broker
Forgerock Service Broker
Google Google Cloud Platform Service Broker
Ibm Websphere Liberty
Microsoft Azure Log Analytics Nozzle Azure Service Broker
Newrelic Dotnet Extension Buildpack Nozzle Service Broker
Pagerduty Service Broker
Pivotal Application Service Cloud Foundry Autoscaling Release Cloud Foundry Command Line Interface Cloud Foundry Command Line Interface Release Cloud Foundry Deployment Cloud Foundry Deployment Concourse Tasks Cloud Foundry Event Alerts Cloud Foundry Healthwatch Cloud Foundry Log Cache Release Cloud Foundry Networking Release Cloud Foundry Notifications Cloud Foundry Routing Release Cloud Foundry Smoke Test Credhub Service Broker For Pcf Metric Registrar Release On Demand Service Broker Pivotal Cloud Foundry Service Broker Single Sign-on
Riverbed Steelcentral Appinternals
Samba Volume Service
Signalsciences Service Broker
Snyk Service Broker
Solace Pubsub\+
Splunk Nozzle
Sumologic Nozzle
Synopsys Seeker Iast Service Broker
Tibco Businessworks Buildpack
Wavefront Wavefront By Vmware Nozzle
Yugabyte Db Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-17T04:29:08.973Z

Reserved: 2019-01-03T00:00:00.000Z

Link: CVE-2019-3800

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-05T17:15:10.960

Modified: 2024-11-21T04:42:33.957

Link: CVE-2019-3800

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses