CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
Metrics
No CVSS v4.0
No CVSS v3.1
Attack Vector Local
Attack Complexity Low
Privileges Required Low
Scope Changed
Confidentiality Impact Low
Integrity Impact Low
Availability Impact Low
User Interaction None
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
This CVE is not in the KEV list.
The EPSS score is 0.00205.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Anynines
Subscribe
|
|
|
Apigee
Subscribe
|
Edge Service Broker
Subscribe
|
|
Appdynamics
Subscribe
|
|
|
Bluemedora
Subscribe
|
Nozzle
Subscribe
|
|
Contrastsecurity
Subscribe
|
Service Broker
Subscribe
|
|
Cyberark
Subscribe
|
Conjur Service Broker
Subscribe
|
|
Datadoghq
Subscribe
|
Application Monitoring
Subscribe
|
|
Datastax
Subscribe
|
Enterprise Service Broker
Subscribe
|
|
Dynatrace
Subscribe
|
Service Broker
Subscribe
|
|
Forgerock
Subscribe
|
Service Broker
Subscribe
|
|
Google
Subscribe
|
Google Cloud Platform Service Broker
Subscribe
|
|
Ibm
Subscribe
|
Websphere Liberty
Subscribe
|
|
Microsoft
Subscribe
|
|
|
Newrelic
Subscribe
|
|
|
Pagerduty
Subscribe
|
Service Broker
Subscribe
|
|
Pivotal
Subscribe
|
Application Service
Subscribe
Cloud Foundry Autoscaling Release
Subscribe
Cloud Foundry Command Line Interface
Subscribe
Cloud Foundry Command Line Interface Release
Subscribe
Cloud Foundry Deployment
Subscribe
Cloud Foundry Deployment Concourse Tasks
Subscribe
Cloud Foundry Event Alerts
Subscribe
Cloud Foundry Healthwatch
Subscribe
Cloud Foundry Log Cache Release
Subscribe
Cloud Foundry Networking Release
Subscribe
Cloud Foundry Notifications
Subscribe
Cloud Foundry Routing Release
Subscribe
Cloud Foundry Smoke Test
Subscribe
Credhub Service Broker For Pcf
Subscribe
Metric Registrar Release
Subscribe
On Demand Service Broker
Subscribe
Pivotal Cloud Foundry Service Broker
Subscribe
Single Sign-on
Subscribe
|
|
Riverbed
Subscribe
|
Steelcentral Appinternals
Subscribe
|
|
Samba
Subscribe
|
Volume Service
Subscribe
|
|
Signalsciences
Subscribe
|
Service Broker
Subscribe
|
|
Snyk
Subscribe
|
Service Broker
Subscribe
|
|
Solace
Subscribe
|
Pubsub\+
Subscribe
|
|
Splunk
Subscribe
|
Nozzle
Subscribe
|
|
Sumologic
Subscribe
|
Nozzle
Subscribe
|
|
Synopsys
Subscribe
|
Seeker Iast Service Broker
Subscribe
|
|
Tibco
Subscribe
|
Businessworks Buildpack
Subscribe
|
|
Wavefront
Subscribe
|
Wavefront By Vmware Nozzle
Subscribe
|
|
Yugabyte
Subscribe
|
Db Enterprise
Subscribe
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13427 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T04:29:08.973Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-3800
No data.
Status : Modified
Published: 2019-08-05T17:15:10.960
Modified: 2024-11-21T04:42:33.957
Link: CVE-2019-3800
No data.
OpenCVE Enrichment
No data.
EUVD