CVE-2018-11044: Input Validation
Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when sending invitation emails. A malicious authenticated user can inject content into an invite to another user, exploiting the trust implied by the source of the email.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11044?
CVE-2018-11044 is a vulnerability in Pivotal Apps Manager included in Pivotal Application Service.
How does CVE-2018-11044 impact Pivotal Application Service?
CVE-2018-11044 allows a malicious authenticated user to inject content into invitation emails.
Which versions of Pivotal Application Service are affected by CVE-2018-11044?
Pivotal Application Service versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.8, 2.0.x prior to 2.0.17, and 1.12.x prior to 1.12.26 are affected by CVE-2018-11044.
What is the severity of CVE-2018-11044?
CVE-2018-11044 has a severity level of medium with a score of 6.5.
How can I fix CVE-2018-11044 in Pivotal Application Service?
To fix CVE-2018-11044, you should upgrade Pivotal Application Service to version 2.2.1, 2.1.8, 2.0.17, or 1.12.26.