CVE Vulnerabilities

CVE-2018-11086

Published: Sep 17, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.

Affected Software

NameVendorStart VersionEnd Version
Pivotal_application_servicePivotal_software2.0.0 (including)2.0.21 (excluding)
Pivotal_application_servicePivotal_software2.1.0 (including)2.1.13 (excluding)
Pivotal_application_servicePivotal_software2.2.0 (including)2.2.5 (excluding)

References