« Volver al listado

CVE-2019-3801

Estado: ModificadaCrítica (9.8)—

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-3801",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 8.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 2.2
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Cloud Foundry",
          "product": "CredHub",
          "versions": [
            {
              "status": "affected",
              "version": "2.1",
              "lessThan": "2.1.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.9",
              "lessThan": "1.9.10",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Cloud Foundry",
          "product": "UAA Release (OSS)",
          "versions": [
            {
              "status": "affected",
              "version": "All",
              "lessThan": "v64.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Cloud Foundry",
          "product": "cf-deployment",
          "versions": [
            {
              "status": "affected",
              "version": "All",
              "lessThan": "v7.9.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Pivotal",
          "product": "UAA Release (LTS)",
          "versions": [
            {
              "status": "affected",
              "version": "v60",
              "lessThan": "v60.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "v64",
              "lessThan": "v64.1",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-04-25T21:29:00.823",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/108104",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.cloudfoundry.org/blog/cve-2019-3801",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/108104",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cloudfoundry.org/blog/cve-2019-3801",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-494"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-319"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component."
    },
    {
      "lang": "es",
      "value": "Cloud Foundry cf-deployment versiones anteriores a 7.9.0, contiene componentes java que son empleados en un protocolo inseguro cuando se construyen dependencias. Un atacante malicioso remoto sin autenticar, podría secuestrar la entrada DNS de la dependencia e inyectar código malicioso en el componente."
    }
  ],
  "lastModified": "2026-06-17T02:35:37.100",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01930C56-713D-49E3-9A19-348AAC0CAED1",
              "versionEndExcluding": "7.9.0"
            },
            {
              "criteria": "cpe:2.3:a:cloudfoundry:credhub:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "077881F9-5C62-4F45-9634-7459A4BC84EE",
              "versionEndExcluding": "1.9.10",
              "versionStartIncluding": "1.9"
            },
            {
              "criteria": "cpe:2.3:a:cloudfoundry:credhub:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08BA1621-4676-4BDD-94FA-4EC2A873E3A2",
              "versionEndExcluding": "2.1.3",
              "versionStartIncluding": "2.1"
            },
            {
              "criteria": "cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50BE60C9-0B65-4253-B52D-5CE79F501568",
              "versionEndExcluding": "64.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}