Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Rabbitmq MEDIUM 6.5
CVE-2018-1279

Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tena…

Mitigation only
Fix from $1,600 2018-12-10
Spring Batch Admin HIGH 8.8
CVE-2018-1230

Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticated user could craft a malicio…

Mitigation only
Fix from $1,950 2018-03-21
Spring Batch Admin MEDIUM 6.1
CVE-2018-1229

Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with netw…

Mitigation only
Fix from $1,600 2018-03-21
Concourse HIGH 7.5
CVE-2018-1227

Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a D…

Mitigation only
Fix from $1,950 2018-03-13
Spring Advanced Message Queuing Protocol CRITICAL 9.8
CVE-2017-8045

In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being c…

Mitigation only
Fix from $2,300 2017-11-27
Credhub Release HIGH 8.8
CVE-2017-8038

In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation…

Mitigation only
Fix from $1,950 2017-11-27
Cf Deployment HIGH 7.5
CVE-2017-14390

In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to be drained to unintended locat…

Mitigation only
Fix from $1,950 2017-11-27
Grootfs HIGH 7.8
CVE-2017-14388

Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the groo…

Mitigation only
Fix from $1,950 2017-11-13
Cloud Foundry Elastic Runtime CRITICAL 9.8
CVE-2017-2773

An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23…

Mitigation only
Fix from $2,300 2017-06-13
Cloud Foundry Elastic Runtime CRITICAL 9.8
CVE-2017-4955

An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28…

Mitigation only
Fix from $2,300 2017-06-13
Cloud Foundry Elastic Runtime HIGH 8.8
CVE-2017-4959

An issue was discovered in Pivotal PCF Elastic Runtime 1.8.x versions prior to 1.8.29 and 1.9.x versions prior to 1.9.7. Pivotal Cloud Foundry deploy…

Mitigation only
Fix from $1,950 2017-06-13
Gemfire For Pivotal Cloud Foundry CRITICAL 9.8
CVE-2016-9885

An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The gfsh (Geode Shell) endpoint, …

Mitigation only
Fix from $2,300 2017-01-06
Cloud Foundry Ops Manager HIGH 7.4
CVE-2016-6657

An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply …

Mitigation only
Fix from $1,950 2016-12-16
Cloud Foundry Cf Mysql HIGH 7.5
CVE-2016-6653

The MariaDB audit_plugin component in Pivotal Cloud Foundry (PCF) cf-mysql-release 27 and 28 allows remote attackers to obtain sensitive information …

Mitigation only
Fix from $1,950 2016-10-06
Rabbitmq HIGH 7.5
CVE-2016-0929

The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might al…

Mitigation only
Fix from $1,950 2016-09-18
Cloud Foundry Elastic Runtime MEDIUM 6.1
CVE-2016-0927

Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web scr…

Mitigation only
Fix from $1,600 2016-09-18