CVE-2019-3801
Published: Apr 25, 2019
Modified: Sep 17, 2024
CVSS v3.0
8.7
Description
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
| Vendor | Product | Versions |
|---|---|---|
Cloud Foundry | CredHub | affected 2.1 - < 2.1.3affected 1.9 - < 1.9.10 |
Cloud Foundry | UAA Release (OSS) | affected All - < v64.0 |
Cloud Foundry | cf-deployment | affected All - < v7.9.0 |
Pivotal | UAA Release (LTS) | affected v60 - < v60.2affected v64 - < v64.1 |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now