Cloud Foundry cf-deployment CVE-2019-3801 Security Bypass Vulnerability
BID:108104
CVE-2019-3801 |Info
Cloud Foundry cf-deployment CVE-2019-3801 Security Bypass Vulnerability
| Bugtraq ID: | 108104 |
| Class: | Design Error |
| CVE: |
CVE-2019-3801 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2019 12:00AM |
| Updated: | Apr 25 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Pivotal Software Application Service 2.2.15 Pivotal Software Application Service 2.2.14 Pivotal Software Application Service 2.2.13 Pivotal Software Application Service 2.2.12 Pivotal Software Application Service 2.2.11 Pivotal Software Application Service 2.2.10 Pivotal Software Application Service 2.2.9 Pivotal Software Application Service 2.2.8 Pivotal Software Application Service 2.2.7 Pivotal Software Application Service 2.2.6 Pivotal Software Application Service 2.2.5 Pivotal Software Application Service 2.2.4 Pivotal Software Application Service 2.2.3 Pivotal Software Application Service 2.2.2 Pivotal Software Application Service 2.2.1 Pivotal Software Application Service 2.2 Pivotal Software Application Service 2.1.20 Pivotal Software Application Service 2.1.19 Pivotal Software Application Service 2.1.18 Pivotal Software Application Service 2.1.17 Pivotal Software Application Service 2.1.16 Pivotal Software Application Service 2.1.15 Pivotal Software Application Service 2.1.14 Pivotal Software Application Service 2.1.13 Pivotal Software Application Service 2.1.12 Pivotal Software Application Service 2.1.11 Pivotal Software Application Service 2.1.10 Pivotal Software Application Service 2.1.9 Pivotal Software Application Service 2.1.8 Pivotal Software Application Service 2.1.7 Pivotal Software Application Service 2.1.6 Pivotal Software Application Service 2.1.5 Pivotal Software Application Service 2.1.4 Pivotal Software Application Service 2.1.3 Pivotal Software Application Service 2.1.2 Pivotal Software Application Service 2.1.1 Pivotal Software Application Service 2.1 Pivotal Software Application Service 2.0.24 Pivotal Software Application Service 2.0.23 Pivotal Software Application Service 2.0.22 Pivotal Software Application Service 2.0.21 Pivotal Software Application Service 2.0.20 Pivotal Software Application Service 2.0.19 Pivotal Software Application Service 2.0.18 Pivotal Software Application Service 2.0.17 Pivotal Software Application Service 2.0.16 Pivotal Software Application Service 2.0.15 Pivotal Software Application Service 2.0.14 Pivotal Software Application Service 2.0.13 Pivotal Software Application Service 2.0.12 Pivotal Software Application Service 2.0.11 Pivotal Software Application Service 2.0.10 Pivotal Software Application Service 2.0.9 Pivotal Software Application Service 2.0.8 Pivotal Software Application Service 2.0.7 Pivotal Software Application Service 2.0.6 Pivotal Software Application Service 2.0.5 Pivotal Software Application Service 2.0.4 Pivotal Software Application Service 2.0.3 Pivotal Software Application Service 2.0.2 Pivotal Software Application Service 2.0.1 Pivotal Software Application Service 2.0 Cloud Foundry UAA 63.0 Cloud Foundry CredHub 2.1.2 Cloud Foundry CredHub 2.1.1 Cloud Foundry CredHub 2.1 Cloud Foundry CredHub 1.9 Cloud Foundry cf-deployment 7.8 Cloud Foundry cf-deployment 7.7 Cloud Foundry cf-deployment 7.6 Cloud Foundry cf-deployment 7.5 Cloud Foundry cf-deployment 7.4 Cloud Foundry cf-deployment 7.3 |
| Not Vulnerable: |
Pivotal Software Application Service 2.3 Cloud Foundry UAA 64.0 Cloud Foundry CredHub 2.1.3 Cloud Foundry CredHub 1.9.10 Cloud Foundry cf-deployment 7.9 |
Discussion
Cloud Foundry cf-deployment CVE-2019-3801 Security Bypass Vulnerability
Cloud Foundry cf-deployment is prone to a security-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
Cloud Foundry cf-deployment prior to 7.9.0 are vulnerable.
Cloud Foundry cf-deployment is prone to a security-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
Cloud Foundry cf-deployment prior to 7.9.0 are vulnerable.
Exploit / POC
Cloud Foundry cf-deployment CVE-2019-3801 Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cloud Foundry cf-deployment CVE-2019-3801 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cloud Foundry cf-deployment CVE-2019-3801 Security Bypass Vulnerability
References:
References:
- Cloud Foundry cf-deployment Github Repository (Github)
- Cloud Foundry Home Page (Cloud Foundry)
- CVE-2019-3801: Java Projects using HTTP to fetch dependencies (Pivotal Software)
- CVE-2019-3801: Java Projects using HTTP to fetch dependencies (Cloud Foundry)