Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Concourse MEDIUM 5.4
CVE-2022-31683

Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body inclu…

Fix: 6.7.9 / 7.8.3+
Fix from $1,600 2022-12-19
Concourse CRITICAL 10.0
CVE-2020-5415

Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of conf…

Fix: 6.3.1 / 6.4.1+
Fix from $2,300 2020-08-12
Spring Batch HIGH 8.1
CVE-2020-5411

When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixe…

Fix: after 4.2.2
Fix from $1,950 2020-06-11
Concourse MEDIUM 6.1
CVE-2020-5409

Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could co…

Fix: 5.2.8 / 5.5.10+
Fix from $1,600 2020-05-14
Spring Security HIGH 8.8
CVE-2020-5407

Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. Wh…

Fix: 5.2.4 / 5.3.2+
Fix from $1,950 2020-05-13
Spring Framework MEDIUM 5.4
CVE-2013-6430

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape …

Fix: 3.2.2+
Fix from $1,600 2020-01-10
Operations Manager MEDIUM 6.5
CVE-2019-11292

Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameter…

Fix: 2.4.27 / 2.5.24+
Fix from $1,600 2020-01-09
Pivotal Application Service HIGH 8.8
CVE-2019-11280

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x…

Fix: 2.3.18 / 2.4.14+
Fix from $1,950 2019-09-20
Application Service MEDIUM 5.4
CVE-2019-11276

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x …

Fix: 2.3.16 / 2.4.12+
Fix from $1,600 2019-08-19
Application Service HIGH 7.5
CVE-2019-11270

Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can by…

Fix: 2.3.15 / 2.3.22+
Fix from $1,950 2019-08-05
Cloud Foundry Uaa MEDIUM 5.4
CVE-2019-3794

Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking att…

Fix: 73.4.0+
Fix from $1,600 2019-07-18
Cloud Foundry Uaa Release HIGH 8.8
CVE-2019-3787

Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user na…

Fix: 73.0.0+
Fix from $1,950 2019-06-19
Spring Security Oauth MEDIUM 5.4
CVE-2019-11269EPSS 9%

Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported vers…

Fix: 2.0.18 / 2.1.5+
Fix from $1,600 2019-06-12
Operations Manager MEDIUM 5.4
CVE-2019-3790

The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to …

Fix: 2.2.23 / 2.3.16+
Fix from $1,600 2019-06-06
Spring Data Java Persistance Api MEDIUM 5.3
CVE-2019-3802

This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, E…

Fix: after 2.1.7
Fix from $1,600 2019-06-03
Spring Data Java Persistence Api MEDIUM 5.3
CVE-2019-3797

This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘…

Fix: after 2.1.5
Fix from $1,600 2019-05-06
Application Service CRITICAL 9.8
CVE-2019-3793

Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an i…

Fix: 665.0.28 / 666.0.21+
Fix from $2,300 2019-04-24
Concourse HIGH 7.5
CVE-2019-3792

Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can c…

Fix: 5.0.1+
Fix from $1,950 2019-04-01
Application Service CRITICAL 9.8
CVE-2019-3777

Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cl…

Fix: 2.2.12 / 2.3.7+
Fix from $2,300 2019-03-07
Spring Security Oauth MEDIUM 6.5
CVE-2019-3778EPSS 15%

Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported ve…

Fix: 2.0.17 / 2.1.4+
Fix from $1,600 2019-03-07
Operations Manager MEDIUM 5.4
CVE-2019-3776

Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2…

Fix: 2.1.20 / 2.2.16+
Fix from $1,600 2019-03-07
Spring Web Services CRITICAL 9.8
CVE-2019-3773

Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (…

Fix: after 8.1.0
Fix from $2,300 2019-01-18
Spring Batch CRITICAL 9.8
CVE-2019-3774

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML…

Fix: after 4.0.1
Fix from $2,300 2019-01-18
Concourse HIGH 7.5
CVE-2019-3803

Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a us…

Fix: 4.2.2+
Fix from $1,950 2019-01-12
Concourse MEDIUM 5.4
CVE-2018-15798

Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could co…

Fix: 4.2.2+
Fix from $1,600 2018-12-19
Cloud Foundry Uaa Release HIGH 8.8
CVE-2018-15754

Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain acc…

Fix: 66.0+
Fix from $1,950 2018-12-13
Rabbitmq MEDIUM 6.5
CVE-2018-1279

Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tena…

Mitigation only
Fix from $1,600 2018-12-10
Cloud Foundry Nfs Volume HIGH 8.8
CVE-2018-15797

Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when runn…

Fix: 1.2.5 / 1.5.4+
Fix from $1,950 2018-12-05
Broker Api CRITICAL 9.8
CVE-2018-15759

Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated ma…

Fix: 0.24.0 / 3.0.2+
Fix from $2,300 2018-11-19
Cloud Foundry Uaa HIGH 8.8
CVE-2018-15761

Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalat…

Fix: 4.23.0 / 64.0+
Fix from $1,950 2018-11-19