CRITICAL
Java Projects using HTTP to fetch dependencies
Published Apr 25, 2019
9.8
CRITICALCVSS 3.1
EPSS 0.59%
Description
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
Affected products
-
Affected
- ≥ 1.9, < 1.9.10
- ≥ 2.1, < 2.1.3
-
Affected
- ≥ All, < v64.0
-
Affected
- ≥ All, < v7.9.0
-
Affected
- ≥ v60, < v60.2
- ≥ v64, < v64.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Cloud Foundry | CredHub | unknown | Affected
|
| Cloud Foundry | UAA Release (OSS) | unknown | Affected
|
| Cloud Foundry | CF-Deployment | unknown | Affected
|
| Pivotal | UAA Release (LTS) | unknown | Affected
|
OR
- < 7.9.0
- ≥ 1.9 · < 1.9.10
- ≥ 2.1 · < 2.1.3
- < 64.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- http://www.securityfocus.com/bid/108104 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-13428 Advisory
- https://www.cloudfoundry.org/blog/cve-2019-3801 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/108104 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-13428 | Advisory | |
| https://www.cloudfoundry.org/blog/cve-2019-3801 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published Apr 25, 2019
Updated Sep 17, 2024
Reserved Jan 3, 2019
Link CVE-2019-3801
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data