SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-3800

A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

HIGH 7.8EPSS 2.09%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

CVSS 3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
2.09% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-522, CWE-200
Affected
pivotal/cloud foundry command line interface · pivotal/cloud foundry command line interface release · pivotal/cloud foundry deployment · pivotal/cloud foundry deployment concourse tasks · pivotal/cloud foundry log cache release · pivotal/cloud foundry networking release · pivotal/cloud foundry notifications · pivotal/cloud foundry routing release · pivotal/cloud foundry smoke test · pivotal/application service · pivotal/cloud foundry autoscaling release · pivotal/cloud foundry event alerts · pivotal/cloud foundry healthwatch · pivotal/credhub service broker for pcf · pivotal/metric registrar release · pivotal/on demand service broker · pivotal/pivotal cloud foundry service broker · pivotal/single sign-on · anynines/elasticsearch · anynines/logme · +35 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.