Pivotal Software Pivotal Application Service vulnerabilities
7 known vulnerabilities affecting pivotal_software/pivotal_application_service.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2019-11275MEDIUMCVSS 4.3≥ 2.3.0, ≤ 2.3.18≥ 2.4.0, ≤ 2.4.14+2 more2019-10-01
CVE-2019-11275 [MEDIUM] CWE-74 CVE-2019-11275: Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22,
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula
nvd
CVE-2019-11280HIGHCVSS 8.8≥ 2.3.0, < 2.3.18≥ 2.4.0, < 2.4.14+2 more2019-09-20
CVE-2019-11280 [HIGH] CWE-269 CVE-2019-11280: Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote authenticated user can gain additional privileges by inviting themselves to spaces
nvd
CVE-2018-11086HIGHCVSS 8.8≥ 2.0.0, < 2.0.21≥ 2.1.0, < 2.1.13+1 more2018-09-17
CVE-2018-11086 [HIGH] CVE-2018-11086: Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to
Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.
nvd
CVE-2018-11088HIGHCVSS 8.8≥ 2.0.0, < 2.0.21≥ 2.1.0, < 2.1.13+1 more2018-09-17
CVE-2018-11088 [HIGH] CVE-2018-11088: Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 pr
Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.
nvd
CVE-2018-11044MEDIUMCVSS 6.5≥ 1.12.0, < 1.12.26≥ 2.0.0, < 2.0.17+2 more2018-07-24
CVE-2018-11044 [MEDIUM] CWE-20 CVE-2018-11044: Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.
Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when sending invitation emails. A malicious authenticated user can inject content into an invite to another user, exploiting the trust imp
nvd
CVE-2018-1278MEDIUMCVSS 6.5≥ 1.12.0, < 1.12.22≥ 2.0.0, < 2.0.13+1 more2018-05-11
CVE-2018-1278 [MEDIUM] CWE-863 CVE-2018-1278: Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior
Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be discovered. Accepting this invitation gives unauthorized access to view th
nvd
CVE-2018-1200MEDIUMCVSS 6.5≥ 1.11.0, < 1.11.26≥ 1.12.0, < 1.12.14+1 more2018-03-16
CVE-2018-1200 [MEDIUM] CWE-200 CVE-2018-1200: Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and
Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links.
nvd