Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Operations_manager | Pivotal_software | 2.0.0 (including) | 2.0.24 (excluding) |
Operations_manager | Pivotal_software | 2.1.0 (including) | 2.1.15 (excluding) |
Operations_manager | Pivotal_software | 2.2.0 (including) | 2.2.7 (excluding) |
Operations_manager | Pivotal_software | 2.3.0 (including) | 2.3.1 (excluding) |