Vulnerabilities > Pivotal Software

DATE CVE VULNERABILITY TITLE RISK
2017-11-27 CVE-2017-8045 Deserialization of Untrusted Data vulnerability in Pivotal Software Spring Advanced Message Queuing Protocol
In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string.
network
low complexity
pivotal-software CWE-502
critical
9.8
2017-11-27 CVE-2017-8038 Unspecified vulnerability in Pivotal Software Credhub-Release 1.1.0
In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential.
network
low complexity
pivotal-software
8.8
2017-11-27 CVE-2017-8028 Improper Authentication vulnerability in multiple products
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct.
network
high complexity
pivotal-software debian CWE-287
8.1
2017-11-27 CVE-2017-14390 Unspecified vulnerability in Pivotal Software Cf-Deployment 0.35.0
In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to be drained to unintended locations.
network
low complexity
pivotal-software
7.5
2017-11-13 CVE-2017-14388 Improper Input Validation vulnerability in Pivotal Software Grootfs
Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the grootfs volume cache.
local
low complexity
pivotal-software CWE-20
7.8
2017-10-24 CVE-2015-5173 Information Exposure vulnerability in multiple products
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."
network
low complexity
pivotal-software cloudfoundry CWE-200
8.8
2017-10-24 CVE-2015-5172 Weak Password Recovery Mechanism for Forgotten Password vulnerability in multiple products
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
network
low complexity
pivotal-software cloudfoundry CWE-640
critical
9.8
2017-10-24 CVE-2015-5171 Insufficient Session Expiration vulnerability in multiple products
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.
network
low complexity
pivotal-software cloudfoundry CWE-613
critical
9.8
2017-10-24 CVE-2015-5170 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
network
low complexity
pivotal-software cloudfoundry CWE-352
8.8
2017-07-10 CVE-2017-8032 Improper Privilege Management vulnerability in multiple products
In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.17, 24.x versions prior to v24.12.
network
high complexity
pivotal-software cloudfoundry CWE-269
6.6