Vulnerabilities > Pivotal Software
|2022-04-01||CVE-2022-22950|| Allocation of Resources Without Limits or Throttling vulnerability in Pivotal Software Spring Framework |
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
| 4.0 |
|2021-02-23||CVE-2021-22112||Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in).|| 9.0 |
|2020-09-19||CVE-2020-5421||In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.|| 3.6 |
|2020-08-31||CVE-2020-5419|| Uncontrolled Search Path Element vulnerability in multiple products |
RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution.
| 4.6 |
|2020-08-12||CVE-2020-5415|| Authentication Bypass by Spoofing vulnerability in Pivotal Software Concourse |
Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team.
| 6.4 |
|2020-06-11||CVE-2020-5411|| Deserialization of Untrusted Data vulnerability in Pivotal Software Spring Batch |
When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution.
| 6.8 |
|2020-05-14||CVE-2020-5408|| Use of Insufficiently Random Values vulnerability in multiple products |
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor.
| 4.0 |
|2020-05-14||CVE-2020-5409|| Open Redirect vulnerability in Pivotal Software Concourse |
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow.
| 5.8 |
|2020-05-13||CVE-2020-5407|| Improper Verification of Cryptographic Signature vulnerability in Pivotal Software Spring Security |
Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation.
| 6.5 |
|2020-02-12||CVE-2020-5399|| Cleartext Transmission of Sensitive Information vulnerability in multiple products |
Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS.
| 5.8 |