CVE-2019-11275
- EPSS 0.2%
- Veröffentlicht 01.10.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:20:50
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote...
CVE-2019-11280
- EPSS 0.59%
- Veröffentlicht 20.09.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:20:50
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their or...
CVE-2018-11086
- EPSS 0.34%
- Veröffentlicht 17.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:38
Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to...
CVE-2018-11088
- EPSS 0.34%
- Veröffentlicht 17.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:39
Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be ...
CVE-2018-11044
- EPSS 0.23%
- Veröffentlicht 24.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:33
Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when sending invitation emails. A ma...
CVE-2018-1278
- EPSS 0.33%
- Veröffentlicht 11.05.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:31
Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org ...
CVE-2018-1200
- EPSS 0.38%
- Veröffentlicht 16.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:22
Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links.