Pivotal Software
pivotal_software
144 CVEs • 50 products
Products (50)
Click to collapseToggle
Products (50)
Click to collapse
CVEs (144)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to cert...Show more |
3Oracle Pivotal SoftwareVmware8Communications Element Manager Communications Interactive Session RecorderCommunications Unified Inventory Management+5 moreNov 21, 2024 Feb 23, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A...Show more |
2Broadcom Pivotal Software2Rabbitmq Rabbitmq ServerApr 2, 2025 Aug 31, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation direc...Show more |
1Pivotal Software 1Concourse Nov 21, 2024 Aug 12, 2020 N/A· v4 10.0 CRITICAL· v3 6.4 MEDIUM· v2 Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is...Show more |
1Pivotal Software 1Spring Batch Nov 21, 2024 Jun 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". S...Show more |
2Pivotal Software Vmware2Spring Security Spring SecurityNov 21, 2024 May 14, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of th...Show more |
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an...Show more |
1Pivotal Software 1Spring Security Nov 21, 2024 May 13, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malici...Show more |
2Cloudfoundry Pivotal Software2Cloud Foundry Cf Deployment CredhubNov 21, 2024 Feb 12, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop...Show more |
1Pivotal Software 1Spring Framework Nov 21, 2024 Jan 10, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site...Show more |
1Pivotal Software 1Operations Manager Nov 21, 2024 Jan 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide...Show more |
5Broadcom DebianFedoraproject+2 more5Debian Linux FedoraOpenstack+2 moreApr 2, 2025 Nov 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is v...Show more |
2Cloudfoundry Pivotal Software2Cf Deployment Cloud Foundry Smb VolumeNov 21, 2024 Oct 23, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have be...Show more |
2Cloudfoundry Pivotal Software2Cf Deployment Cloud Foundry UaaNov 21, 2024 Oct 23, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content whic...Show more |
4Debian FedoraprojectPivotal Software+1 more5Debian Linux FedoraOpenstack+2 moreNov 21, 2024 Oct 16, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits p...Show more |
2Pivotal Pivotal Software2Apps Manager Pivotal Application ServiceNov 21, 2024 Oct 1, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain...Show more |
1Pivotal Software 1Pivotal Application Service Nov 21, 2024 Sep 20, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows user...Show more |
1Pivotal Software 1Application Service Nov 21, 2024 Aug 19, 2019 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via S...Show more |
1Pivotal Software 3Application Service Cloud Foundry UaaOperations ManagerNov 21, 2024 Aug 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' an...Show more |
1Pivotal Software 1Pivotal Container Service Nov 21, 2024 Jul 23, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user...Show more |