CVE-2018-11086
17.09.2018, 16:29
Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.Enginsight
Vendor | Product | Version |
---|---|---|
pivotal_software | pivotal_application_service | 2.0.0 ≤ 𝑥 < 2.0.21 |
pivotal_software | pivotal_application_service | 2.1.0 ≤ 𝑥 < 2.1.13 |
pivotal_software | pivotal_application_service | 2.2.0 ≤ 𝑥 < 2.2.5 |
𝑥
= Vulnerable software versions