CVE-2019-3801

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
25/04/2019
Last modified:
29/10/2021

Description

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* 7.9.0 (excluding)
cpe:2.3:a:cloudfoundry:credhub:*:*:*:*:*:*:*:* 1.9 (including) 1.9.10 (excluding)
cpe:2.3:a:cloudfoundry:credhub:*:*:*:*:*:*:*:* 2.1 (including) 2.1.3 (excluding)
cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:* 64.0 (excluding)