CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.16.0"
},
{
"introduced": "0"
},
{
"fixed": "2.2.0"
},
{
"introduced": "0"
},
{
"fixed": "1.7.0"
},
{
"introduced": "0"
},
{
"fixed": "1.1.0"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "3.1.1"
},
{
"introduced": "0"
},
{
"fixed": "1.2.4"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "10.0.0"
},
{
"introduced": "0"
},
{
"fixed": "9.3.0"
},
{
"introduced": "0"
},
{
"fixed": "1.2"
},
{
"introduced": "0"
},
{
"fixed": "0.29.0"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.23.0"
},
{
"introduced": "0"
},
{
"fixed": "1.3.2"
},
{
"introduced": "1.8.0"
},
{
"fixed": "1.8.4"
},
{
"introduced": "0"
},
{
"fixed": "3.11.0"
},
{
"introduced": "0"
},
{
"fixed": "1.0.1"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "6.45.0"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.3.1"
},
{
"introduced": "1.4.0"
},
{
"fixed": "1.4.7"
},
{
"introduced": "0"
},
{
"fixed": "2.1.2"
},
{
"introduced": "0"
},
{
"fixed": "2.1.2"
},
{
"introduced": "0"
},
{
"fixed": "2.1.2"
},
{
"introduced": "0"
},
{
"fixed": "2.1.2"
},
{
"introduced": "0"
},
{
"fixed": "2.1.2"
},
{
"introduced": "0"
},
{
"fixed": "2.1.2"
},
{
"introduced": "0"
},
{
"fixed": "2.1.2"
},
{
"introduced": "0"
},
{
"fixed": "3.1.3"
},
{
"introduced": "0"
},
{
"fixed": "1.1.1"
},
{
"introduced": "0"
},
{
"fixed": "1.4.2"
},
{
"introduced": "0"
},
{
"fixed": "2.1.2"
},
{
"introduced": "0"
},
{
"fixed": "1.4.1"
},
{
"introduced": "0"
},
{
"fixed": "1.4.1"
},
{
"introduced": "0"
},
{
"fixed": "1.1.1"
},
{
"introduced": "0"
},
{
"fixed": "1.1.1"
},
{
"introduced": "0"
},
{
"fixed": "1.1.1"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "58"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "40.0.113"
}
]
},
{
"events": [
{
"introduced": "2.3.0"
},
{
"fixed": "2.3.14"
}
]
},
{
"events": [
{
"introduced": "2.5.0"
},
{
"fixed": "2.5.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "219"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.8"
}
]
},
{
"events": [
{
"introduced": "1.5.0"
},
{
"fixed": "1.5.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.4.13"
}
]
},
{
"events": [
{
"introduced": "1.7.0"
},
{
"fixed": "1.7.5"
}
]
},
{
"events": [
{
"introduced": "1.9.0"
},
{
"fixed": "1.9.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.7.652"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.6.64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.7.712"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.2.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.1.17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.12.64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.21.1-bl516"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.3.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.1.8"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-3800.json"