Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.
2018-09-17T16:29:00.300
2024-11-21T03:42:38.987
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pivotal_software | pivotal_application_service | < 2.0.21 | Yes |
Application | pivotal_software | pivotal_application_service | < 2.1.13 | Yes |
Application | pivotal_software | pivotal_application_service | < 2.2.5 | Yes |