Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2022-31683 Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body inclu… Concourse 6.7.9 / 7.8.3+ Fix from $1,6002022-12-19 CRITICAL 10.0 CVE-2020-5415 Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of conf… Concourse 6.3.1 / 6.4.1+ Fix from $2,3002020-08-12 HIGH 8.1 CVE-2020-5411 When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixe… Spring Batch after 4.2.2 Fix from $1,9502020-06-11 MEDIUM 6.1 CVE-2020-5409 Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could co… Concourse 5.2.8 / 5.5.10+ Fix from $1,6002020-05-14 HIGH 8.8 CVE-2020-5407 Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. Wh… Spring Security 5.2.4 / 5.3.2+ Fix from $1,9502020-05-13 MEDIUM 5.4 CVE-2013-6430 The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape … Spring Framework 3.2.2+ Fix from $1,6002020-01-10 MEDIUM 6.5 CVE-2019-11292 Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameter… Operations Manager 2.4.27 / 2.5.24+ Fix from $1,6002020-01-09 HIGH 8.8 CVE-2019-11280 Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x… Pivotal Application Service 2.3.18 / 2.4.14+ Fix from $1,9502019-09-20 MEDIUM 5.4 CVE-2019-11276 Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x … Application Service 2.3.16 / 2.4.12+ Fix from $1,6002019-08-19 HIGH 7.5 CVE-2019-11270 Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can by… Application Service 2.3.15 / 2.3.22+ Fix from $1,9502019-08-05 MEDIUM 5.4 CVE-2019-3794 Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking att… Cloud Foundry Uaa 73.4.0+ Fix from $1,6002019-07-18 HIGH 8.8 CVE-2019-3787 Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user na… Cloud Foundry Uaa Release 73.0.0+ Fix from $1,9502019-06-19 MEDIUM 5.4 CVE-2019-11269EPSS 9% Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported vers… Spring Security Oauth 2.0.18 / 2.1.5+ Fix from $1,6002019-06-12 MEDIUM 5.4 CVE-2019-3790 The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to … Operations Manager 2.2.23 / 2.3.16+ Fix from $1,6002019-06-06 MEDIUM 5.3 CVE-2019-3802 This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, E… Spring Data Java Persistance Api after 2.1.7 Fix from $1,6002019-06-03 MEDIUM 5.3 CVE-2019-3797 This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘… Spring Data Java Persistence Api after 2.1.5 Fix from $1,6002019-05-06 CRITICAL 9.8 CVE-2019-3793 Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an i… Application Service 665.0.28 / 666.0.21+ Fix from $2,3002019-04-24 HIGH 7.5 CVE-2019-3792 Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can c… Concourse 5.0.1+ Fix from $1,9502019-04-01 CRITICAL 9.8 CVE-2019-3777 Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cl… Application Service 2.2.12 / 2.3.7+ Fix from $2,3002019-03-07 MEDIUM 6.5 CVE-2019-3778EPSS 15% Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported ve… Spring Security Oauth 2.0.17 / 2.1.4+ Fix from $1,6002019-03-07 MEDIUM 5.4 CVE-2019-3776 Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2… Operations Manager 2.1.20 / 2.2.16+ Fix from $1,6002019-03-07 CRITICAL 9.8 CVE-2019-3773 Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (… Spring Web Services after 8.1.0 Fix from $2,3002019-01-18 CRITICAL 9.8 CVE-2019-3774 Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML… Spring Batch after 4.0.1 Fix from $2,3002019-01-18 HIGH 7.5 CVE-2019-3803 Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a us… Concourse 4.2.2+ Fix from $1,9502019-01-12 MEDIUM 5.4 CVE-2018-15798 Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could co… Concourse 4.2.2+ Fix from $1,6002018-12-19 HIGH 8.8 CVE-2018-15754 Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain acc… Cloud Foundry Uaa Release 66.0+ Fix from $1,9502018-12-13 MEDIUM 6.5 CVE-2018-1279 Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tena… Rabbitmq Mitigation only Fix from $1,6002018-12-10 HIGH 8.8 CVE-2018-15797 Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when runn… Cloud Foundry Nfs Volume 1.2.5 / 1.5.4+ Fix from $1,9502018-12-05 CRITICAL 9.8 CVE-2018-15759 Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated ma… Broker Api 0.24.0 / 3.0.2+ Fix from $2,3002018-11-19 HIGH 8.8 CVE-2018-15761 Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalat… Cloud Foundry Uaa 4.23.0 / 64.0+ Fix from $1,9502018-11-19