CVE-2019-3800

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
dellCNA
6.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
pivotalcloud_foundry_command_line_interface
𝑥
< 6.45.0
pivotalcloud_foundry_command_line_interface_release
𝑥
< 1.16.0
pivotalcloud_foundry_deployment
𝑥
< 10.0.0
pivotalcloud_foundry_deployment_concourse_tasks
𝑥
< 9.3.0
pivotalcloud_foundry_log_cache_release
𝑥
< 2.3.1
pivotalcloud_foundry_networking_release
𝑥
< 2.23.0
pivotalcloud_foundry_notifications
𝑥
< 58
pivotalcloud_foundry_routing_release
𝑥
< 0.189.0
pivotalcloud_foundry_smoke_test
𝑥
< 40.0.113
pivotalapplication_service
2.3.0 ≤
𝑥
< 2.3.14
pivotalapplication_service
2.4.0 ≤
𝑥
< 2.4.10
pivotalapplication_service
2.5.0 ≤
𝑥
< 2.5.6
pivotalcloud_foundry_autoscaling_release
𝑥
< 219
pivotalcloud_foundry_event_alerts
𝑥
< 1.2.8
pivotalcloud_foundry_healthwatch
1.4.0 ≤
𝑥
< 1.4.7
pivotalcloud_foundry_healthwatch
1.5.0 ≤
𝑥
< 1.5.4
pivotalcredhub_service_broker_for_pcf
𝑥
< 1.3.2
pivotalmetric_registrar_release
𝑥
< 1.2
pivotalon_demand_service_broker
𝑥
< 0.29.0
pivotalpivotal_cloud_foundry_service_broker
𝑥
< 1.4.13
pivotalsingle_sign-on
1.7.0 ≤
𝑥
< 1.7.5
pivotalsingle_sign-on
1.8.0 ≤
𝑥
< 1.8.4
pivotalsingle_sign-on
1.9.0 ≤
𝑥
< 1.9.1
anynineselasticsearch
𝑥
< 2.1.2
anynineslogme
𝑥
< 2.1.2
anyninesmongodb
𝑥
< 2.1.2
anyninesmysql
𝑥
< 2.1.2
anyninespostgresql
𝑥
< 2.1.2
anyninesrabbitmq
𝑥
< 2.1.2
anyninesredis
𝑥
< 2.1.2
apigeeedge_service_broker
𝑥
< 3.1.3
appdynamicsapplication_analytics
𝑥
< 4.7.652
appdynamicsapplication_performance_monitoring
𝑥
< 4.6.64
appdynamicsplatform_montioring
𝑥
< 4.7.712
bluemedoranozzle
𝑥
< 3.1.1
contrastsecurityservice_broker
𝑥
< 2.2.0
cyberarkconjur_service_broker
𝑥
< 1.1.1
datadoghqapplication_monitoring
𝑥
< 1.7.0
datastaxenterprise_service_broker
𝑥
< 1.0.2
dynatraceservice_broker
𝑥
< 1.4.2
forgerockservice_broker
𝑥
< 2.1.2
googlegoogle_cloud_platform_service_broker
𝑥
< 4.2.3
ibmwebsphere_liberty_
𝑥
< 3.11.0
microsoftazure_log_analytics_nozzle
𝑥
< 1.4.1
microsoftazure_service_broker
𝑥
< 1.4.1
newrelicdotnet_extension_buildpack
𝑥
< 1.1.1
newrelicnozzle
𝑥
< 1.1.17
newrelicservice_broker
𝑥
< 1.12.64
pagerdutyservice_broker
𝑥
< 1.2.4
riverbedsteelcentral_appinternals
𝑥
< 10.21.1-bl516
sambavolume_service
𝑥
< 1.1.1
signalsciencesservice_broker
𝑥
< 1.1.0
snykservice_broker
𝑥
< 1.0.3
solacepubsub\+
𝑥
< 2.3.2
splunknozzle
𝑥
< 1.1.1
sumologicnozzle
𝑥
< 1.0.1
synopsysseeker_iast_service_broker
𝑥
< 1.2.14
tibcobusinessworks_buildpack
𝑥
< 2.4.4
wavefrontwavefront_by_vmware_nozzle
𝑥
< 1.0.2
yugabytedb_enterprise
𝑥
< 1.1.8
𝑥
= Vulnerable software versions