CVE Vulnerabilities

CVE-2018-11088

Published: Sep 17, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.

Affected Software

NameVendorStart VersionEnd Version
Pivotal_application_servicePivotal_software2.0.0 (including)2.0.21 (excluding)
Pivotal_application_servicePivotal_software2.1.0 (including)2.1.13 (excluding)
Pivotal_application_servicePivotal_software2.2.0 (including)2.2.5 (excluding)

References