CVE-2019-3800: Anynines Elasticsearch

High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

Affected products

  • Anynines Elasticsearch: before 2.1.2 (fixed in 2.1.2)
  • Anynines Logme: before 2.1.2 (fixed in 2.1.2)
  • Anynines MongoDB: before 2.1.2 (fixed in 2.1.2)
  • Anynines MySQL: before 2.1.2 (fixed in 2.1.2)
  • Anynines PostgreSQL: before 2.1.2 (fixed in 2.1.2)
  • Anynines Rabbitmq: before 2.1.2 (fixed in 2.1.2)
  • Anynines Redis: before 2.1.2 (fixed in 2.1.2)
  • Apigee Edge Service Broker: before 3.1.3 (fixed in 3.1.3)
  • Appdynamics Application Analytics: before 4.7.652 (fixed in 4.7.652)
  • Appdynamics Application Performance Monitoring: before 4.6.64 (fixed in 4.6.64)
  • Appdynamics Platform Montioring: before 4.7.712 (fixed in 4.7.712)
  • Bluemedora Nozzle: before 3.1.1 (fixed in 3.1.1)
  • Contrastsecurity Service Broker: before 2.2.0 (fixed in 2.2.0)
  • Cyberark Conjur Service Broker: before 1.1.1 (fixed in 1.1.1)
  • Datadoghq Application Monitoring: before 1.7.0 (fixed in 1.7.0)
  • Datastax Enterprise Service Broker: before 1.0.2 (fixed in 1.0.2)
  • Dynatrace Service Broker: before 1.4.2 (fixed in 1.4.2)
  • ForgeRock Service Broker: before 2.1.2 (fixed in 2.1.2)
  • Google Google Cloud Platform Service Broker: before 4.2.3 (fixed in 4.2.3)
  • IBM WebSphere Liberty: before 3.11.0 (fixed in 3.11.0)
  • Microsoft Azure Log Analytics Nozzle: before 1.4.1 (fixed in 1.4.1)
  • Microsoft Azure Service Broker: before 1.4.1 (fixed in 1.4.1)
  • Newrelic Dotnet Extension Buildpack: before 1.1.1 (fixed in 1.1.1)
  • Newrelic Nozzle: before 1.1.17 (fixed in 1.1.17)
  • Newrelic Service Broker: before 1.12.64 (fixed in 1.12.64)
  • and 30 more

Published 2019-08-05. Last modified 2026-06-17.