PT-2019-12223 · Pivotal · Pivotal Application Service
Published
2019-08-19
·
Updated
2020-10-16
·
CVE-2019-11276
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pivotal Application Service versions 2.3.x through 2.3.15
Pivotal Application Service versions 2.4.x through 2.4.11
Pivotal Application Service versions 2.5.x through 2.5.7
Pivotal Application Service versions 2.6.x through 2.6.2
Description
The issue allows an adjacent unauthenticated user to eavesdrop on network traffic and gain access to an unencrypted token. This token can be used to read the type of access a user has over an app. Additionally, the attacker may modify the logging level, potentially leading to lost information.
Recommendations
For Pivotal Application Service versions 2.3.x through 2.3.15, update to version 2.3.16 or later.
For Pivotal Application Service versions 2.4.x through 2.4.11, update to version 2.4.12 or later.
For Pivotal Application Service versions 2.5.x through 2.5.7, update to version 2.5.8 or later.
For Pivotal Application Service versions 2.6.x through 2.6.2, update to version 2.6.3 or later.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pivotal Application Service