VYPR
Medium severity6.3NVD Advisory· Published Aug 5, 2019· Updated Jun 17, 2026

CVE-2019-3800

CVE-2019-3800

Description

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

58

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.