Critical severity9.8NVD Advisory· Published Apr 25, 2019· Updated Jun 17, 2026
CVE-2019-3801
CVE-2019-3801
Description
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*range: <7.9.0
- (no CPE)range: <7.9.0
- (no CPE)range: All
cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*range: <64.0
- (no CPE)range: v60
- Cloud Foundry/CredHubv5Range: 2.1
- Cloud Foundry/UAA Release (OSS)v5Range: All
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/108104nvdThird Party AdvisoryVDB Entry
- www.cloudfoundry.org/blog/cve-2019-3801nvdVendor Advisory
News mentions
0No linked articles in our index yet.