CVE-2019-3780
HIGHCloudfoundry Container Runtime - Insufficiently Protected Credentials
Title source: ruleDescription
Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malicious user with access to the k8s nodes can obtain IAAS credentials allowing the user to escalate privileges to gain access to the IAAS account.
Scores
CVSS v3
8.8
EPSS
0.0038
EPSS Percentile
59.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-260
CWE-522
Status
published
Affected Products (1)
cloudfoundry/container_runtime
< 0.28.0
Timeline
Published
Mar 08, 2019
Tracked Since
Feb 18, 2026