Pivotal
pivotal
30 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (30)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Cloudfoundry Pivotal2Capi Release Cf ReleaseMay 13, 2026 Oct 4, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer...Show more |
2Cloudfoundry Pivotal2Cf Release Routing ReleaseMay 13, 2026 Oct 4, 2017 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for...Show more |
2Cloudfoundry Pivotal4Cf Release Elastic RuntimeUaa Release+1 moreMay 13, 2026 Sep 7, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allo...Show more |
An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security group that overrides security groups set by the operator. |
An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can b...Show more |
1Pivotal 1Spring Security Oauth May 13, 2026 May 25, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user t...Show more |
An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM....Show more |
2Cloudfoundry Pivotal2Cloud Foundry Elastic Runtime Php BuildpackMay 6, 2026 Sep 18, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, plac...Show more |
1Pivotal 1Operations Manager May 6, 2026 Sep 18, 2016 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting...Show more |
1Pivotal 1Cloud Foundry Elastic Runtime May 6, 2026 Sep 18, 2016 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via...Show more |