SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2019-3800

MEDIUM · CVSS 6.3 EPSS 2.09%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-05 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.3. See the original NVD description below for full technical details.

CVE
CVE-2019-3800
Severity
MEDIUM
CVSS
6.3
EPSS
2.09%

Original NVD Description

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

Related CVEs

Other vulnerabilities affecting the same vendor(s)