Skip to main content

Vendor archive

pivotal_software CVEs

Beta · best-effort

144 CVEs tagged to vendor pivotal_software28 Critical, 61 High, 52 Medium, 3 Low, 0 Unrated.

CVE-2022-31683

Published Dec 19, 2022

Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypas…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22112

Published Feb 23, 2021

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is chan…

CVSS 8.8 · High

CVE-2020-5415

Published Aug 12, 2020

Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-5411

Published Jun 11, 2020

When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blackl…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5409

Published May 14, 2020

Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a li…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5407

Published May 13, 2020

Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6430

Published Jan 10, 2020

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11292

Published Jan 9, 2020

Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11276

Published Aug 19, 2019

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a reques…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11273

Published Jul 23, 2019

Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the bill…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3794

Published Jul 18, 2019

Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3790

Published Jun 6, 2019

The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 144 CVEsPage 1 of 6