First published: Fri Sep 20 2019(Updated: )
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote authenticated user can gain additional privileges by inviting themselves to spaces that they should not have access to.
Credit: security@pivotal.io
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Pivotal Application Service | >=2.3.0<2.3.18 | |
Pivotal Software Pivotal Application Service | >=2.4.0<2.4.14 | |
Pivotal Software Pivotal Application Service | >=2.5.0<2.5.10 | |
Pivotal Software Pivotal Application Service | >=2.6.0<2.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11280 is a vulnerability in Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5.
CVE-2019-11280 has a severity rating of 8.8 (high).
The affected software for CVE-2019-11280 is Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5.
A remote authenticated user can gain unauthorized access to organizations by exploiting the invitations microservice in Pivotal Apps Manager.
You can find more information about CVE-2019-11280 at the following link: [Pivotal Security Advisory](https://pivotal.io/security/cve-2019-11280)