CVE-2019-3781

command_line_interface: Insertion of Sensitive Information Into Debugging Code (CVE-2019-3781)

Description

Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password.

Source: NVDCVELISTV5

Metrics

Severity
high
no public PoC known
8.8
Source: nvd-v3
69.3 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
1.3 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2019-03-07 19:00 UTC
CWE-215

Weakness classes (CWE)

  • CWE-215Base

    Insertion of Sensitive Information Into Debugging Code

    The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • cloudfoundry

    command_line_interface6.43.0

References & sources

IDCVE-2019-3781