First published: Fri Mar 16 2018(Updated: )
Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Pivotal Application Service | >=1.11.0<1.11.26 | |
Pivotal Software Pivotal Application Service | >=1.12.0<1.12.14 | |
Pivotal Software Pivotal Application Service | >=2.0.0<2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1200 is medium with a severity value of 6.5.
The affected software for CVE-2018-1200 is Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5).
An attacker can exploit CVE-2018-1200 by sending specially-crafted links to Apps Manager for PCF, allowing them to perform unprivileged remote file read in its container.
Yes, the references for CVE-2018-1200 are http://www.securityfocus.com/bid/103042 and https://pivotal.io/security/cve-2018-1200.
The Common Weakness Enumeration (CWE) for CVE-2018-1200 is CWE-200.