Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3801

Опубликовано: 25 апр. 2019
Источник: nvd
CVSS3: 8.7
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
Версия до 7.9.0 (исключая)
cpe:2.3:a:cloudfoundry:credhub:*:*:*:*:*:*:*:*
Версия от 1.9 (включая) до 1.9.10 (исключая)
cpe:2.3:a:cloudfoundry:credhub:*:*:*:*:*:*:*:*
Версия от 2.1 (включая) до 2.1.3 (исключая)
cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*
Версия до 64.0 (исключая)

EPSS

Процентиль: 47%
0.00588
Низкий

8.7 High

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-494
CWE-319

Связанные уязвимости

CVSS3: 9.8
github
больше 4 лет назад

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.

EPSS

Процентиль: 47%
0.00588
Низкий

8.7 High

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-494
CWE-319