CVE-2019-3800: CF CLI writes the client id and secret to config file

Published Aug 5, 2019
·
Updated

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

Affected Software

60 affected components
Pivotal Cloud Foundry Command Line Interface<6.45.0
Pivotal Cloud Foundry Command Line Interface Release<1.16.0
Pivotal Cloud Foundry Deployment<10.0.0
Pivotal Cloud Foundry Deployment Concourse Tasks<9.3.0
Pivotal Cloud Foundry Log Cache Release<2.3.1
Pivotal Cloud Foundry Networking Release<2.23.0
Pivotal Cloud Foundry Notifications<58
Pivotal Cloud Foundry Routing Release<0.189.0
Pivotal Cloud Foundry Smoke Test<40.0.113
Pivotal Application Service>=2.3.0<2.3.14
Pivotal Application Service>=2.4.0<2.4.10
Pivotal Application Service>=2.5.0<2.5.6
Pivotal Cloud Foundry Autoscaling Release<219
Pivotal Cloud Foundry Event Alerts<1.2.8
Pivotal Cloud Foundry Healthwatch>=1.4.0<1.4.7
Pivotal Cloud Foundry Healthwatch>=1.5.0<1.5.4
Pivotal Credhub Service Broker For Pcf<1.3.2
Pivotal Metric Registrar Release<1.2
Pivotal On Demand Service Broker<0.29.0
Pivotal Pivotal Cloud Foundry Service Broker Aws<1.4.13
Pivotal Single Sign-on Cloud Foundry>=1.7.0<1.7.5
Pivotal Single Sign-on Cloud Foundry>=1.8.0<1.8.4
Pivotal Single Sign-on Cloud Foundry>=1.9.0<1.9.1
Anynines Elasticsearch Pivotal Cloud Foundry<2.1.2
Anynines Logme Pivotal Cloud Foundry<2.1.2
Anynines Mongodb Pivotal Cloud Foundry<2.1.2
Anynines Mysql Pivotal Cloud Foundry<2.1.2
Anynines Postgresql Pivotal Cloud Foundry<2.1.2
Anynines Rabbitmq Pivotal Cloud Foundry<2.1.2
Anynines Redis Pivotal Cloud Foundry<2.1.2
Apigee Edge Service Broker Pivotal Cloud Foundry<3.1.3
Appdynamics Application Analytics Pivotal Cloud Foundry<4.7.652
Appdynamics Application Performance Monitoring Pivotal Cloud Foundry<4.6.64
Appdynamics Platform Montioring Pivotal Cloud Foundry<4.7.712
Bluemedora Nozzle Pivotal Cloud Foundry<3.1.1
Contrastsecurity Service Broker Pivotal Cloud Foundry<2.2.0
CyberArk Conjur Service Broker Pivotal Cloud Foundry<1.1.1
datadoghq Application Monitoring Pivotal Cloud Foundry<1.7.0
Datastax Enterprise Service Broker Pivotal Cloud Foundry<1.0.2
Dynatrace Service Broker Pivotal Cloud Foundry<1.4.2
ForgeRock Service Broker Pivotal Cloud Foundry<2.1.2
Google Google Cloud Platform Service Broker Pivotal Cloud Foundry<4.2.3
Pivotal Cloud Foundry<3.11.0
Microsoft Azure Log Analytics Nozzle Pivotal Cloud Foundry<1.4.1
Microsoft Azure Service Broker Pivotal Cloud Foundry<1.4.1
Newrelic Dotnet Extension Buildpack Pivotal Cloud Foundry<1.1.1
Newrelic Nozzle Pivotal Cloud Foundry<1.1.17
Newrelic Service Broker Pivotal Cloud Foundry<1.12.64
PagerDuty Service Broker Pivotal Cloud Foundry<1.2.4
Riverbed Steelcentral Appinternals Pivotal Cloud Foundry<10.21.1-bl516
Samba Volume Service Pivotal Cloud Foundry<1.1.1
Signalsciences Service Broker Pivotal Cloud Foundry<1.1.0
Snyk Service Broker Pivotal Cloud Foundry<1.0.3
Solace Pubsub\+ Pivotal Cloud Foundry<2.3.2
Splunk Nozzle Pivotal Cloud Foundry<1.1.1
Sumologic Nozzle Pivotal Cloud Foundry<1.0.1
Synopsys Seeker Iast Service Broker Pivotal Cloud Foundry<1.2.14
TIBCO Businessworks Buildpack Pivotal Cloud Foundry<2.4.4
Wavefront Wavefront By Vmware Nozzle Pivotal Cloud Foundry<1.0.2
Yugabyte Db Enterprise Pivotal Cloud Foundry<1.1.8

Event History

Aug 5, 2019
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-3800?

CVE-2019-3800 is considered a medium severity vulnerability due to potential unauthorized access to sensitive client credentials.

2

How do I fix CVE-2019-3800?

To mitigate CVE-2019-3800, upgrade to CF CLI version 6.45.0 or later.

3

Who is affected by CVE-2019-3800?

CVE-2019-3800 affects users of CF CLI versions prior to 6.45.0 who authenticate using the --client-credentials flag.

4

What impact does CVE-2019-3800 have?

CVE-2019-3800 allows a local authenticated user to access sensitive client credentials stored in the CF CLI config file.

5

Is there a workaround for CVE-2019-3800?

As a workaround, users can manually remove sensitive credentials from the CF CLI config file until an upgrade can be performed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203