Vulnerability Details CVE-2019-3801
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 22.4%
CVSS Severity
CVSS v3 Score 8.7
CVSS v2 Score 5.0
Products affected by CVE-2019-3801
-
cpe:2.3:a:cloudfoundry:cf-deployment:-
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.0.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.0.2
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.10.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.11.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.12.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.13.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.14.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.15.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.16.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.17.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.18.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.19.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.2.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.2.2
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.20.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.21.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.22.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.23.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.24.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.25.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.26.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.27.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.28.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.29.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.30.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.31.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.32.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.32.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.33.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.34.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.35.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.36.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.37.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.9.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.9.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.10.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.11.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.12.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.13.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.14.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.15.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.16.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.17.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.18.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.19.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.20.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.21.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.22.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.23.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.24.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.25.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.26.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.27.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.28.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.29.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.3.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.30.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.31.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.32.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.33.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.34.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.35.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.36.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.37.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.38.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.39.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.40.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.9.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.9.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.10.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.9.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.8.0
-
cpe:2.3:a:cloudfoundry:credhub:1.9.1
-
cpe:2.3:a:cloudfoundry:credhub:1.9.2
-
cpe:2.3:a:cloudfoundry:credhub:1.9.3
-
cpe:2.3:a:cloudfoundry:credhub:1.9.4
-
cpe:2.3:a:cloudfoundry:credhub:1.9.5
-
cpe:2.3:a:cloudfoundry:credhub:1.9.6
-
cpe:2.3:a:cloudfoundry:credhub:1.9.7
-
cpe:2.3:a:cloudfoundry:credhub:1.9.8
-
cpe:2.3:a:cloudfoundry:credhub:1.9.9
-
cpe:2.3:a:cloudfoundry:credhub:2.1.0
-
cpe:2.3:a:cloudfoundry:credhub:2.1.1
-
cpe:2.3:a:cloudfoundry:credhub:2.1.2
-
cpe:2.3:a:cloudfoundry:uaa_release:10.0
-
cpe:2.3:a:cloudfoundry:uaa_release:11.0
-
cpe:2.3:a:cloudfoundry:uaa_release:11.1
-
cpe:2.3:a:cloudfoundry:uaa_release:11.2
-
cpe:2.3:a:cloudfoundry:uaa_release:11.3
-
cpe:2.3:a:cloudfoundry:uaa_release:11.4
-
cpe:2.3:a:cloudfoundry:uaa_release:11.5
-
cpe:2.3:a:cloudfoundry:uaa_release:11.7
-
cpe:2.3:a:cloudfoundry:uaa_release:12.0
-
cpe:2.3:a:cloudfoundry:uaa_release:12.1
-
cpe:2.3:a:cloudfoundry:uaa_release:12.2
-
cpe:2.3:a:cloudfoundry:uaa_release:12.3
-
cpe:2.3:a:cloudfoundry:uaa_release:12.4
-
cpe:2.3:a:cloudfoundry:uaa_release:12.5
-
cpe:2.3:a:cloudfoundry:uaa_release:12.6
-
cpe:2.3:a:cloudfoundry:uaa_release:13.0
-
cpe:2.3:a:cloudfoundry:uaa_release:13.1
-
cpe:2.3:a:cloudfoundry:uaa_release:13.10
-
cpe:2.3:a:cloudfoundry:uaa_release:13.11
-
cpe:2.3:a:cloudfoundry:uaa_release:13.12
-
cpe:2.3:a:cloudfoundry:uaa_release:13.13
-
cpe:2.3:a:cloudfoundry:uaa_release:13.14
-
cpe:2.3:a:cloudfoundry:uaa_release:13.15
-
cpe:2.3:a:cloudfoundry:uaa_release:13.16
-
cpe:2.3:a:cloudfoundry:uaa_release:13.17
-
cpe:2.3:a:cloudfoundry:uaa_release:13.18
-
cpe:2.3:a:cloudfoundry:uaa_release:13.2
-
cpe:2.3:a:cloudfoundry:uaa_release:13.3
-
cpe:2.3:a:cloudfoundry:uaa_release:13.4
-
cpe:2.3:a:cloudfoundry:uaa_release:13.5
-
cpe:2.3:a:cloudfoundry:uaa_release:13.6
-
cpe:2.3:a:cloudfoundry:uaa_release:13.7
-
cpe:2.3:a:cloudfoundry:uaa_release:13.8
-
cpe:2.3:a:cloudfoundry:uaa_release:13.9
-
cpe:2.3:a:cloudfoundry:uaa_release:14.0
-
cpe:2.3:a:cloudfoundry:uaa_release:15.0
-
cpe:2.3:a:cloudfoundry:uaa_release:16.0
-
cpe:2.3:a:cloudfoundry:uaa_release:17.0
-
cpe:2.3:a:cloudfoundry:uaa_release:18.0
-
cpe:2.3:a:cloudfoundry:uaa_release:19.0
-
cpe:2.3:a:cloudfoundry:uaa_release:2.0
-
cpe:2.3:a:cloudfoundry:uaa_release:20.0
-
cpe:2.3:a:cloudfoundry:uaa_release:21.0
-
cpe:2.3:a:cloudfoundry:uaa_release:22.0
-
cpe:2.3:a:cloudfoundry:uaa_release:23.0
-
cpe:2.3:a:cloudfoundry:uaa_release:24.0
-
cpe:2.3:a:cloudfoundry:uaa_release:24.1
-
cpe:2.3:a:cloudfoundry:uaa_release:24.10
-
cpe:2.3:a:cloudfoundry:uaa_release:24.11
-
cpe:2.3:a:cloudfoundry:uaa_release:24.12
-
cpe:2.3:a:cloudfoundry:uaa_release:24.13
-
cpe:2.3:a:cloudfoundry:uaa_release:24.14
-
cpe:2.3:a:cloudfoundry:uaa_release:24.2
-
cpe:2.3:a:cloudfoundry:uaa_release:24.3
-
cpe:2.3:a:cloudfoundry:uaa_release:24.4
-
cpe:2.3:a:cloudfoundry:uaa_release:24.5
-
cpe:2.3:a:cloudfoundry:uaa_release:24.6
-
cpe:2.3:a:cloudfoundry:uaa_release:24.7
-
cpe:2.3:a:cloudfoundry:uaa_release:24.8
-
cpe:2.3:a:cloudfoundry:uaa_release:24.9
-
cpe:2.3:a:cloudfoundry:uaa_release:25.0
-
cpe:2.3:a:cloudfoundry:uaa_release:26.0
-
cpe:2.3:a:cloudfoundry:uaa_release:27.0
-
cpe:2.3:a:cloudfoundry:uaa_release:28.0
-
cpe:2.3:a:cloudfoundry:uaa_release:29.0
-
cpe:2.3:a:cloudfoundry:uaa_release:3.0
-
cpe:2.3:a:cloudfoundry:uaa_release:30.0
-
cpe:2.3:a:cloudfoundry:uaa_release:30.1
-
cpe:2.3:a:cloudfoundry:uaa_release:30.2
-
cpe:2.3:a:cloudfoundry:uaa_release:30.3
-
cpe:2.3:a:cloudfoundry:uaa_release:30.4
-
cpe:2.3:a:cloudfoundry:uaa_release:30.5
-
cpe:2.3:a:cloudfoundry:uaa_release:30.6
-
cpe:2.3:a:cloudfoundry:uaa_release:30.7
-
cpe:2.3:a:cloudfoundry:uaa_release:30.8
-
cpe:2.3:a:cloudfoundry:uaa_release:30.9
-
cpe:2.3:a:cloudfoundry:uaa_release:31.0
-
cpe:2.3:a:cloudfoundry:uaa_release:32.0
-
cpe:2.3:a:cloudfoundry:uaa_release:33.0
-
cpe:2.3:a:cloudfoundry:uaa_release:34.0
-
cpe:2.3:a:cloudfoundry:uaa_release:34.1
-
cpe:2.3:a:cloudfoundry:uaa_release:34.2
-
cpe:2.3:a:cloudfoundry:uaa_release:34.3
-
cpe:2.3:a:cloudfoundry:uaa_release:35.0
-
cpe:2.3:a:cloudfoundry:uaa_release:36.0
-
cpe:2.3:a:cloudfoundry:uaa_release:37.0
-
cpe:2.3:a:cloudfoundry:uaa_release:38.0
-
cpe:2.3:a:cloudfoundry:uaa_release:39.0
-
cpe:2.3:a:cloudfoundry:uaa_release:4.0
-
cpe:2.3:a:cloudfoundry:uaa_release:40.0
-
cpe:2.3:a:cloudfoundry:uaa_release:41.0
-
cpe:2.3:a:cloudfoundry:uaa_release:41.1
-
cpe:2.3:a:cloudfoundry:uaa_release:43.0
-
cpe:2.3:a:cloudfoundry:uaa_release:44.0
-
cpe:2.3:a:cloudfoundry:uaa_release:45.0
-
cpe:2.3:a:cloudfoundry:uaa_release:45.1
-
cpe:2.3:a:cloudfoundry:uaa_release:45.10
-
cpe:2.3:a:cloudfoundry:uaa_release:45.11
-
cpe:2.3:a:cloudfoundry:uaa_release:45.2
-
cpe:2.3:a:cloudfoundry:uaa_release:45.3
-
cpe:2.3:a:cloudfoundry:uaa_release:45.4
-
cpe:2.3:a:cloudfoundry:uaa_release:45.5
-
cpe:2.3:a:cloudfoundry:uaa_release:45.6
-
cpe:2.3:a:cloudfoundry:uaa_release:45.7
-
cpe:2.3:a:cloudfoundry:uaa_release:45.8
-
cpe:2.3:a:cloudfoundry:uaa_release:45.9
-
cpe:2.3:a:cloudfoundry:uaa_release:48.0
-
cpe:2.3:a:cloudfoundry:uaa_release:5.0
-
cpe:2.3:a:cloudfoundry:uaa_release:50.0
-
cpe:2.3:a:cloudfoundry:uaa_release:51.0
-
cpe:2.3:a:cloudfoundry:uaa_release:52.0
-
cpe:2.3:a:cloudfoundry:uaa_release:52.1
-
cpe:2.3:a:cloudfoundry:uaa_release:52.10
-
cpe:2.3:a:cloudfoundry:uaa_release:52.2
-
cpe:2.3:a:cloudfoundry:uaa_release:52.4
-
cpe:2.3:a:cloudfoundry:uaa_release:52.5
-
cpe:2.3:a:cloudfoundry:uaa_release:52.6
-
cpe:2.3:a:cloudfoundry:uaa_release:52.7
-
cpe:2.3:a:cloudfoundry:uaa_release:52.8
-
cpe:2.3:a:cloudfoundry:uaa_release:52.9
-
cpe:2.3:a:cloudfoundry:uaa_release:53.0
-
cpe:2.3:a:cloudfoundry:uaa_release:53.1
-
cpe:2.3:a:cloudfoundry:uaa_release:53.2
-
cpe:2.3:a:cloudfoundry:uaa_release:53.3
-
cpe:2.3:a:cloudfoundry:uaa_release:54.0
-
cpe:2.3:a:cloudfoundry:uaa_release:55.0
-
cpe:2.3:a:cloudfoundry:uaa_release:55.1
-
cpe:2.3:a:cloudfoundry:uaa_release:55.2
-
cpe:2.3:a:cloudfoundry:uaa_release:56.0
-
cpe:2.3:a:cloudfoundry:uaa_release:57.0
-
cpe:2.3:a:cloudfoundry:uaa_release:57.1
-
cpe:2.3:a:cloudfoundry:uaa_release:57.2
-
cpe:2.3:a:cloudfoundry:uaa_release:57.3
-
cpe:2.3:a:cloudfoundry:uaa_release:57.4
-
cpe:2.3:a:cloudfoundry:uaa_release:58.0
-
cpe:2.3:a:cloudfoundry:uaa_release:58.1
-
cpe:2.3:a:cloudfoundry:uaa_release:59.0
-
cpe:2.3:a:cloudfoundry:uaa_release:6.0
-
cpe:2.3:a:cloudfoundry:uaa_release:60.0
-
cpe:2.3:a:cloudfoundry:uaa_release:60.2
-
cpe:2.3:a:cloudfoundry:uaa_release:61.0
-
cpe:2.3:a:cloudfoundry:uaa_release:62.0
-
cpe:2.3:a:cloudfoundry:uaa_release:63.0
-
cpe:2.3:a:cloudfoundry:uaa_release:7.0
-
cpe:2.3:a:cloudfoundry:uaa_release:8.0
-
cpe:2.3:a:cloudfoundry:uaa_release:9.0