Pivotal
pivotal
30 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (30)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pivotal 2Cloud Foundry Deployment Cloud Foundry Routing ReleaseJun 3, 2025 Jan 12, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availabili...Show more |
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition....Show more |
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifica...Show more |
1Pivotal 3Cloud Foundry Nfs Volume Cloud Foundry NotificationsCloud Foundry Smb VolumeDec 16, 2024 Jun 16, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3....Show more |
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affe...Show more |
2Oracle Pivotal2Communications Design Studio Spring Security OauthNov 21, 2024 Apr 21, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 <Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 C...Show more |
2Linuxfoundation Pivotal2Harbor Vmware Harbor RegistryNov 21, 2024 Mar 20, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform. |
2Linuxfoundation Pivotal2Harbor Vmware Harbor RegistryNov 21, 2024 Mar 20, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform. |
2Linuxfoundation Pivotal2Harbor Vmware Harbor RegistryNov 21, 2024 Mar 20, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform. |
2Linuxfoundation Pivotal2Harbor Vmware Harbor RegistryNov 21, 2024 Mar 20, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform. |
Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of producing a 400 response. |
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to h...Show more |
In Pivotal tc Server, 3.x versions prior to 3.2.19 and 4.x versions prior to 4.0.10, and Pivotal tc Runtimes, 7.x versions prior to 7.0.99.B, 8.x versions prior to 8.5.47.A, and 9.x versions prior to 9.0.27.A, when a tc...Show more |
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they hav...Show more |
2Pivotal Pivotal Software2Apps Manager Pivotal Application ServiceNov 21, 2024 Oct 1, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain...Show more |
27Anynines ApigeeAppdynamics+24 more55Application Analytics Application MonitoringApplication Performance Monitoring+52 moreNov 21, 2024 Aug 5, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with acces...Show more |
1Pivotal 1Cloud Foundry Container Runtime Nov 21, 2024 Sep 17, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentia...Show more |
The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote...Show more |
2Cloudfoundry Pivotal3Cf Release UaaUaa BoshNov 21, 2024 Jan 4, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross...Show more |
An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can b...Show more |