CVE-2019-3780
container_runtime: Password in Configuration File (CVE-2019-3780)
criticalEPSS 1.4%
Description
Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malicious user with access to the k8s nodes can obtain IAAS credentials allowing the user to escalate privileges to gain access to the IAAS account.
Metrics
Severity
critical
88.36
no public PoC known
9.1
Published
2019-03-08 16:00 UTC
CWE-260
Weakness classes (CWE)
CWE-260Base
Password in Configuration File
The product stores a password in a configuration file that might be accessible to actors who do not know the password.
cwe.mitre.org →
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
cloudfoundry
container_runtime0.28.0
References & sources
IDCVE-2019-3780