VYPR
Critical severity9.8NVD Advisory· Published Apr 25, 2019· Updated Jun 17, 2026

CVE-2019-3801

CVE-2019-3801

Description

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*range: <7.9.0
    • (no CPE)range: <7.9.0
    • (no CPE)range: All
  • cpe:2.3:a:cloudfoundry:credhub:*:*:*:*:*:*:*:*
    Range: >=1.9,<1.9.10
  • cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*range: <64.0
    • (no CPE)range: v60
  • Cloud Foundry/CredHubv5
    Range: 2.1
  • Cloud Foundry/UAA Release (OSS)v5
    Range: All

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.