PT-2019-12220 · Pivotal · Pivotal Container Service
Publicado
2019-07-23
·
Atualizado
2020-10-07
·
CVE-2019-11273
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7
Pivotal Container Services (PKS) versions 1.4.x prior to 1.4.1
Description
The issue concerns a vulnerable component in Pivotal Container Services (PKS) that logs the
username and password to the billing database. A remote authenticated user with access to those logs may be able to retrieve non-sensitive information.Recommendations
For versions 1.3.x prior to 1.3.7, update to version 1.3.7 or later.
For versions 1.4.x prior to 1.4.1, update to version 1.4.1 or later.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pivotal Container Service