CVE-2019-3801
cf-deployment: Download of Code Without Integrity Check (CVE-2019-3801)
Description
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
Metrics
Weakness classes (CWE)
CWE-494Base
Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
cwe.mitre.org →
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
cloudfoundry
cf-deployment7.9.0
cloudfoundry
credhub1.9 – 1.9.10
cloudfoundry
credhub2.1 – 2.1.3
cloudfoundry
uaa_release64.0