Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2022-31683
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body inclu…
Concourse
6.7.9 / 7.8.3+
CRITICAL 10.0
CVE-2020-5415
Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of conf…
Concourse
6.3.1 / 6.4.1+
HIGH 8.1
CVE-2020-5411
When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixe…
Spring Batch
after 4.2.2
MEDIUM 6.1
CVE-2020-5409
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could co…
Concourse
5.2.8 / 5.5.10+
HIGH 8.8
CVE-2020-5407
Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. Wh…
Spring Security
5.2.4 / 5.3.2+
MEDIUM 5.4
CVE-2013-6430
The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape …
Spring Framework
3.2.2+
MEDIUM 6.5
CVE-2019-11292
Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameter…
Operations Manager
2.4.27 / 2.5.24+
HIGH 8.8
CVE-2019-11280
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x…
Pivotal Application Service
2.3.18 / 2.4.14+
MEDIUM 5.4
CVE-2019-11276
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x …
Application Service
2.3.16 / 2.4.12+
HIGH 7.5
CVE-2019-11270
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can by…
Application Service
2.3.15 / 2.3.22+
MEDIUM 5.4
CVE-2019-3794
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking att…
Cloud Foundry Uaa
73.4.0+
HIGH 8.8
CVE-2019-3787
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user na…
Cloud Foundry Uaa Release
73.0.0+
MEDIUM 5.4
CVE-2019-11269EPSS 9%
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported vers…
Spring Security Oauth
2.0.18 / 2.1.5+
MEDIUM 5.4
CVE-2019-3790
The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to …
Operations Manager
2.2.23 / 2.3.16+
MEDIUM 5.3
CVE-2019-3802
This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, E…
Spring Data Java Persistance Api
after 2.1.7
MEDIUM 5.3
CVE-2019-3797
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘…
Spring Data Java Persistence Api
after 2.1.5
CRITICAL 9.8
CVE-2019-3793
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an i…
Application Service
665.0.28 / 666.0.21+
HIGH 7.5
CVE-2019-3792
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can c…
Concourse
5.0.1+
CRITICAL 9.8
CVE-2019-3777
Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cl…
Application Service
2.2.12 / 2.3.7+
MEDIUM 6.5
CVE-2019-3778EPSS 15%
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported ve…
Spring Security Oauth
2.0.17 / 2.1.4+
MEDIUM 5.4
CVE-2019-3776
Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2…
Operations Manager
2.1.20 / 2.2.16+
CRITICAL 9.8
CVE-2019-3773
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (…
Spring Web Services
after 8.1.0
CRITICAL 9.8
CVE-2019-3774
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML…
Spring Batch
after 4.0.1
HIGH 7.5
CVE-2019-3803
Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a us…
Concourse
4.2.2+
MEDIUM 5.4
CVE-2018-15798
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could co…
Concourse
4.2.2+
HIGH 8.8
CVE-2018-15754
Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain acc…
Cloud Foundry Uaa Release
66.0+
MEDIUM 6.5
CVE-2018-1279
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tena…
Rabbitmq
Mitigation only
HIGH 8.8
CVE-2018-15797
Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when runn…
Cloud Foundry Nfs Volume
1.2.5 / 1.5.4+
CRITICAL 9.8
CVE-2018-15759
Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated ma…
Broker Api
0.24.0 / 3.0.2+
HIGH 8.8
CVE-2018-15761
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalat…
Cloud Foundry Uaa
4.23.0 / 64.0+