CVE-2019-3780

HIGH

Cloudfoundry Container Runtime - Insufficiently Protected Credentials

Title source: rule

Description

Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malicious user with access to the k8s nodes can obtain IAAS credentials allowing the user to escalate privileges to gain access to the IAAS account.

Scores

CVSS v3 8.8
EPSS 0.0038
EPSS Percentile 59.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-260 CWE-522
Status published

Affected Products (1)

cloudfoundry/container_runtime < 0.28.0

Timeline

Published Mar 08, 2019
Tracked Since Feb 18, 2026