Vulnerabilities > Pivotal > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-10-01 CVE-2019-11275 Improper Neutralization of Formula Elements in a CSV File vulnerability in multiple products
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed.
network
low complexity
pivotal pivotal-software CWE-1236
4.0
2018-09-17 CVE-2018-1223 Information Exposure Through Log Files vulnerability in Pivotal Cloud Foundry Container Runtime
Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs.
network
low complexity
pivotal CWE-532
4.0
2018-06-11 CVE-2017-3203 Deserialization of Untrusted Data vulnerability in Pivotal Spring-Flex
The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable.
network
pivotal CWE-502
6.8
2018-01-04 CVE-2018-1190 Cross-site Scripting vulnerability in multiple products
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0.
4.3
2017-11-27 CVE-2017-8039 Insecure Default Initialization of Resource vulnerability in Pivotal Spring web Flow
An issue was discovered in Pivotal Spring Web Flow through 2.4.5.
network
pivotal CWE-1188
4.3
2017-10-04 CVE-2017-8048 In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. 6.8
2017-10-04 CVE-2017-8047 Open Redirect vulnerability in multiple products
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect.
5.8
2017-09-07 CVE-2016-0732 Improper Privilege Management vulnerability in multiple products
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
network
low complexity
cloudfoundry pivotal CWE-269
6.5
2017-06-13 CVE-2017-4975 Incorrect Default Permissions vulnerability in Pivotal PCF Tile Generator
An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0.
network
low complexity
pivotal CWE-276
5.0
2017-06-13 CVE-2017-4971 Insecure Default Initialization of Resource vulnerability in Pivotal Spring web Flow
An issue was discovered in Pivotal Spring Web Flow through 2.4.4.
network
pivotal CWE-1188
4.3