Description
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13427 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. |
References
History
No history.
Subscriptions
Anynines
Subscribe
Elasticsearch
Subscribe
Logme
Subscribe
Mongodb
Subscribe
Mysql
Subscribe
Postgresql
Subscribe
Rabbitmq
Subscribe
Redis
Subscribe
Apigee
Subscribe
Edge Service Broker
Subscribe
Appdynamics
Subscribe
Application Analytics
Subscribe
Application Performance Monitoring
Subscribe
Platform Montioring
Subscribe
Bluemedora
Subscribe
Nozzle
Subscribe
Contrastsecurity
Subscribe
Service Broker
Subscribe
Cyberark
Subscribe
Conjur Service Broker
Subscribe
Datadoghq
Subscribe
Application Monitoring
Subscribe
Datastax
Subscribe
Enterprise Service Broker
Subscribe
Dynatrace
Subscribe
Service Broker
Subscribe
Forgerock
Subscribe
Service Broker
Subscribe
Google
Subscribe
Google Cloud Platform Service Broker
Subscribe
Ibm
Subscribe
Websphere Liberty
Subscribe
Microsoft
Subscribe
Azure Log Analytics Nozzle
Subscribe
Azure Service Broker
Subscribe
Newrelic
Subscribe
Dotnet Extension Buildpack
Subscribe
Nozzle
Subscribe
Service Broker
Subscribe
Pagerduty
Subscribe
Service Broker
Subscribe
Pivotal
Subscribe
Application Service
Subscribe
Cloud Foundry Autoscaling Release
Subscribe
Cloud Foundry Command Line Interface
Subscribe
Cloud Foundry Command Line Interface Release
Subscribe
Cloud Foundry Deployment
Subscribe
Cloud Foundry Deployment Concourse Tasks
Subscribe
Cloud Foundry Event Alerts
Subscribe
Cloud Foundry Healthwatch
Subscribe
Cloud Foundry Log Cache Release
Subscribe
Cloud Foundry Networking Release
Subscribe
Cloud Foundry Notifications
Subscribe
Cloud Foundry Routing Release
Subscribe
Cloud Foundry Smoke Test
Subscribe
Credhub Service Broker For Pcf
Subscribe
Metric Registrar Release
Subscribe
On Demand Service Broker
Subscribe
Pivotal Cloud Foundry Service Broker
Subscribe
Single Sign-on
Subscribe
Riverbed
Subscribe
Steelcentral Appinternals
Subscribe
Samba
Subscribe
Volume Service
Subscribe
Signalsciences
Subscribe
Service Broker
Subscribe
Snyk
Subscribe
Service Broker
Subscribe
Solace
Subscribe
Pubsub\+
Subscribe
Splunk
Subscribe
Nozzle
Subscribe
Sumologic
Subscribe
Nozzle
Subscribe
Synopsys
Subscribe
Seeker Iast Service Broker
Subscribe
Tibco
Subscribe
Businessworks Buildpack
Subscribe
Wavefront
Subscribe
Wavefront By Vmware Nozzle
Subscribe
Yugabyte
Subscribe
Db Enterprise
Subscribe
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T04:29:08.973Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3800
No data.
Status : Modified
Published: 2019-08-05T17:15:10.960
Modified: 2024-11-21T04:42:33.957
Link: CVE-2019-3800
No data.
OpenCVE Enrichment
No data.
EUVD