Skip to main content

Vendor archive

pivotal CVEs

Beta · best-effort

30 CVEs tagged to vendor pivotal2 Critical, 16 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2023-34054

Published Nov 28, 2023

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may caus…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34062

Published Nov 15, 2023

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31684

Published Oct 19, 2022

Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5403

Published Mar 3, 2020

Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of producing a 400 response.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5404

Published Mar 3, 2020

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11288

Published Jan 27, 2020

In Pivotal tc Server, 3.x versions prior to 3.2.19 and 4.x versions prior to 4.0.10, and Pivotal tc Runtimes, 7.x versions prior to 7.0.99.B, 8.x versions prior to 8.5.47.A, and 9…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11284

Published Oct 17, 2019

Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credent…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1223

Published Sep 17, 2018

Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3203

Published Jun 11, 2018

The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8039

Published Nov 27, 2017

An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disable…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8048

Published Oct 4, 2017

In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4975

Published Jun 13, 2017

An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security group that overrides security…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4971

Published Jun 13, 2017

An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disable…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2