CVE-2019-3781: Cloudfoundry Command Line Interface

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password.

Affected products

  • Cloudfoundry Command Line Interface: before 6.43.0 (fixed in 6.43.0)

Published 2019-03-07. Last modified 2026-06-17.