PT-2018-10264 · Pivotal · Pivotal Application Service+1

Publicado

2018-07-24

·

Atualizado

2018-10-01

·

CVE-2018-11044

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pivotal Apps Manager included in Pivotal Application Service versions 2.2.x prior to 2.2.1 Pivotal Apps Manager included in Pivotal Application Service versions 2.1.x prior to 2.1.8 Pivotal Apps Manager included in Pivotal Application Service versions 2.0.x prior to 2.0.17 Pivotal Apps Manager included in Pivotal Application Service versions 1.12.x prior to 1.12.26
Description The issue concerns the failure to escape all user-provided content when sending invitation emails. This allows a malicious authenticated user to inject content into an invite to another user, exploiting the trust implied by the source of the email.
Recommendations For versions 2.2.x prior to 2.2.1, update to version 2.2.1 or later. For versions 2.1.x prior to 2.1.8, update to version 2.1.8 or later. For versions 2.0.x prior to 2.0.17, update to version 2.0.17 or later. For versions 1.12.x prior to 1.12.26, update to version 1.12.26 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11044

Produtos afetados

Pivotal Application Service
Pivotal Apps Manager