Filtered by vendor Pivotal Software
Subscribe
Filtered by product Pivotal Application Service
Subscribe
Search
Total
3 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-11280 | 1 Pivotal Software | 1 Pivotal Application Service | 2019-10-09 | 6.5 MEDIUM | 8.8 HIGH |
| Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote authenticated user can gain additional privileges by inviting themselves to spaces that they should not have access to. | |||||
| CVE-2018-11086 | 1 Pivotal Software | 1 Pivotal Application Service | 2019-10-03 | 4.0 MEDIUM | 8.8 HIGH |
| Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role. | |||||
| CVE-2018-11088 | 1 Pivotal Software | 1 Pivotal Application Service | 2019-10-03 | 4.0 MEDIUM | 8.8 HIGH |
| Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role. | |||||
