Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user could listen to network traffic and gain access to the authorization credentials used to make the invitation requests.
2019-04-24T16:29:02.263
2024-11-21T04:42:33.183
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pivotal_software | application_service | < 665.0.28 | Yes |
Application | pivotal_software | application_service | < 666.0.21 | Yes |
Application | pivotal_software | application_service | < 667.0.7 | Yes |