CVE-2019-3800

Description

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.205

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in MongoDB 1.7.0Windows
Multiple vulnerabilities affected in Mysql 8.0.5Windows
Multiple vulnerabilities affected in Postgresql 11.4Windows
Multiple vulnerabilities affected in Redis 5.0.3Windows
Multiple Vulnerabilities are affected in Mysql 8.0.5Windows
Multiple vulnerabilities affected in MongoDB 1.7.0 (For Linux)Linux
Multiple vulnerabilities affected in Mysql 8.0.5 (For Linux)Linux
Multiple vulnerabilities affected in Postgresql 11.4 (For Linux)Linux
Multiple vulnerabilities affected in Redis 5.0.3 (For Linux)Linux
Multiple Vulnerabilities are affected in Mysql 8.0.5 (For Linux)Linux
Insufficiently Protected Credentials Vulnerability (CVE-2019-3800)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234