Description
Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persistent config file. A local authenticated malicious user with access to the CredHub CLI config file can use these credentials to retrieve and modify credentials stored in CredHub that are authorized to the targeted user.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13413 | Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persistent config file. A local authenticated malicious user with access to the CredHub CLI config file can use these credentials to retrieve and modify credentials stored in CredHub that are authorized to the targeted user. |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T23:36:58.237Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3782
No data.
Status : Modified
Published: 2019-02-13T16:29:00.357
Modified: 2024-11-21T04:42:31.947
Link: CVE-2019-3782
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD