CVE-2018-15762: Pivotal Operations Manager gives all users heightened privileges
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15762?
CVE-2018-15762 is a vulnerability in Pivotal Operations Manager that allows for privilege escalation.
Which versions of Pivotal Operations Manager are affected by CVE-2018-15762?
Pivotal Operations Manager versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1 are affected by CVE-2018-15762.
What is the severity of CVE-2018-15762?
CVE-2018-15762 has a severity rating of critical.
How can I fix CVE-2018-15762?
To fix CVE-2018-15762, you should update Pivotal Operations Manager to version 2.0.24, 2.1.15, 2.2.7, or 2.3.1.
Where can I find more information about CVE-2018-15762?
You can find more information about CVE-2018-15762 at the following link: [CVE-2018-15762](https://pivotal.io/security/cve-2018-15762).