CVE-2019-3801Download of Code Without Integrity Check in Foundry Cf-deployment

Severity
9.8CRITICALNVD
EPSS
0.1%
top 78.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25
Latest updateMay 24

Description

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

CVEListV5cloud_foundry/cf-deploymentAllv7.9.0
NVDcloudfoundry/credhub1.91.9.10+1
CVEListV5cloud_foundry/credhub2.12.1.3+1

🔴Vulnerability Details

2
GHSA
GHSA-4w8g-vwqf-w48w: Cloud Foundry cf-deployment, versions prior to 72022-05-24
CVEList
Java Projects using HTTP to fetch dependencies2019-04-25
CVE-2019-3801 — Foundry Cf-deployment vulnerability | cvebase