Vulnerabilities > Pivotal > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-06-16 CVE-2023-20885 Information Exposure Through Log Files vulnerability in Pivotal products
Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to 5.0.27, 7.1.X versions prior to 7.1.19.
network
low complexity
pivotal CWE-532
6.5
2022-10-19 CVE-2022-31684 Unspecified vulnerability in Pivotal Reactor Netty
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests.
network
low complexity
pivotal
4.3
2022-04-21 CVE-2022-22969 <Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application.
network
low complexity
pivotal oracle
6.5
2020-03-20 CVE-2019-19026 SQL Injection vulnerability in multiple products
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
network
low complexity
linuxfoundation pivotal CWE-89
4.9
2020-03-03 CVE-2020-5404 Insufficiently Protected Credentials vulnerability in Pivotal Reactor Netty
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain.
network
high complexity
pivotal CWE-522
5.9
2019-10-01 CVE-2019-11275 Improper Neutralization of Formula Elements in a CSV File vulnerability in multiple products
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed.
network
low complexity
pivotal pivotal-software CWE-1236
4.3
2018-01-04 CVE-2018-1190 Cross-site Scripting vulnerability in multiple products
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0.
network
low complexity
pivotal cloudfoundry CWE-79
6.1
2017-11-27 CVE-2017-8039 Insecure Default Initialization of Resource vulnerability in Pivotal Spring web Flow
An issue was discovered in Pivotal Spring Web Flow through 2.4.5.
network
high complexity
pivotal CWE-1188
5.9
2017-10-04 CVE-2017-8047 Open Redirect vulnerability in multiple products
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect.
network
low complexity
pivotal cloudfoundry CWE-601
6.1
2017-06-13 CVE-2017-4971 Insecure Default Initialization of Resource vulnerability in Pivotal Spring web Flow
An issue was discovered in Pivotal Spring Web Flow through 2.4.4.
network
high complexity
pivotal CWE-1188
5.9