The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 2.8 | 5.9 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cloudfoundry | user_account_and_authentication | 2.7.1 |
| pivotal | elastic_runtime | 1.6.2 |
| pivotal | elastic_runtime | 1.6.13 |
| cloudfoundry | user_account_and_authentication | 2.2.5 |
| cloudfoundry | uaa-release | 4 |
| cloudfoundry | user_account_and_authentication | 2.2.3 |
| cloudfoundry | user_account_and_authentication | 2.6.0 |
| cloudfoundry | uaa-release | 2 |
| pivotal | elastic_runtime | 1.6.12 |
| cloudfoundry | user_account_and_authentication | 2.5.2 |
| pivotal | elastic_runtime | 1.6.4 |
| cloudfoundry | user_account_and_authentication | 2.1.0 |
| cloudfoundry | user_account_and_authentication | 2.6.1 |
| cloudfoundry | user_account_and_authentication | 2.0.3 |
| pivotal | elastic_runtime | 1.6.9 |
| pivotal | elastic_runtime | 1.6.10 |
| cloudfoundry | user_account_and_authentication | 2.2.1 |
| cloudfoundry | user_account_and_authentication | 2.3.1.1 |
| cloudfoundry | user_account_and_authentication | 2.5.1 |
| pivotal | elastic_runtime | 1.6.1 |
| cloudfoundry | user_account_and_authentication | 2.4.0 |
| pivotal | elastic_runtime | 1.6.0 |
| pivotal | elastic_runtime | 1.6.3 |
| cloudfoundry | user_account_and_authentication | 2.0.1 |
| pivotal | elastic_runtime | 1.6.8 |
| cloudfoundry | user_account_and_authentication | 2.7.0 |
| cloudfoundry | user_account_and_authentication | 2.5.0 |
| cloudfoundry | user_account_and_authentication | 2.7.2 |
| cloudfoundry | user_account_and_authentication | 2.2.0 |
| cloudfoundry | cf-release | * |
| cloudfoundry | user_account_and_authentication | 2.7.0.2 |
| cloudfoundry | user_account_and_authentication | 2.2.4.1 |
| cloudfoundry | user_account_and_authentication | 2.6.2 |
| pivotal | elastic_runtime | 1.6.11 |
| cloudfoundry | user_account_and_authentication | 2.2.5.3 |
| cloudfoundry | user_account_and_authentication | 2.7.0.3 |
| cloudfoundry | user_account_and_authentication | 2.0.2 |
| cloudfoundry | user_account_and_authentication | 2.0.0 |
| pivotal | elastic_runtime | 1.6.7 |
| cloudfoundry | uaa-release | 3 |
| cloudfoundry | user_account_and_authentication | 2.2.6 |
| cloudfoundry | user_account_and_authentication | 2.3.0 |
| cloudfoundry | user_account_and_authentication | 2.7.3 |
| cloudfoundry | user_account_and_authentication | 2.3.1 |
| cloudfoundry | user_account_and_authentication | 2.2.5.2 |
| cloudfoundry | user_account_and_authentication | 2.7.0.1 |
| pivotal | elastic_runtime | 1.6.5 |
| cloudfoundry | user_account_and_authentication | 2.2.4 |
| cloudfoundry | user_account_and_authentication | 2.2.2 |
| cloudfoundry | user_account_and_authentication | 2.4.1 |
| pivotal | elastic_runtime | 1.6.6 |
Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pivotal | cloud_foundry_elastic_runtime | 1.7.7 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.4 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.6 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.5 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.1 |
| pivotal | cloud_foundry_elastic_runtime | * |
| pivotal | cloud_foundry_elastic_runtime | 1.7.2 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.0 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.3 |
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period during which these VMs exist.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pivotal | operations_manager | 1.7.9 |
| pivotal | operations_manager | 1.7.6 |
| pivotal | operations_manager | 1.7.5 |
| pivotal | operations_manager | 1.7.4 |
| pivotal | operations_manager | 1.7.8 |
| pivotal | operations_manager | 1.7.3 |
| pivotal | operations_manager | 1.7.7 |
| pivotal | operations_manager | 1.7.2 |
| pivotal | operations_manager | * |
| pivotal | operations_manager | 1.7.1 |
| pivotal | operations_manager | 1.7.0 |
An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pivotal | bosh_stemcell | 3146.13 |
| pivotal | bosh_stemcell | * |
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the value for response_type.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-19,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pivotal | spring_security_oauth | 1.0.4 |
| pivotal | spring_security_oauth | 1.0.0 |
| pivotal | spring_security_oauth | 2.0.8 |
| pivotal | spring_security_oauth | 1.0.3 |
| pivotal | spring_security_oauth | 2.0.7 |
| pivotal | spring_security_oauth | 2.0.4 |
| pivotal | spring_security_oauth | 1.0.5 |
| pivotal | spring_security_oauth | 2.0.9 |
| pivotal | spring_security_oauth | 2.0.6 |
| pivotal | spring_security_oauth | 1.0.2 |
| pivotal | spring_security_oauth | 2.0.5 |
| pivotal | spring_security_oauth | 2.0.1 |
| pivotal | spring_security_oauth | 2.0.0 |
| pivotal | spring_security_oauth | 2.0.3 |
| pivotal | spring_security_oauth | 1.0.1 |
| pivotal | spring_security_oauth | 2.0.2 |
Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive information via an HTTP GET request for this file.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pivotal | cloud_foundry_elastic_runtime | 1.7.7 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.4 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.12 |
| cloudfoundry | php-buildpack | * |
| pivotal | cloud_foundry_elastic_runtime | 1.7.11 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.16 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.18 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.10 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.3 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.17 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.6 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.8 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.5 |
| pivotal | cloud_foundry_elastic_runtime | * |
| pivotal | cloud_foundry_elastic_runtime | 1.7.1 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.2 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.14 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.0 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.15 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.9 |
| pivotal | cloud_foundry_elastic_runtime | 1.7.13 |
The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI server connection may be able to send serialized Java objects that execute arbitrary code when deserialized.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-502,CWE-502,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pivotal | spring-flex | * |
An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security group that overrides security groups set by the operator.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-276,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pivotal | pcf_tile_generator | * |
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user credentials or other sensitive data. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pivotal | routing-release | * |
| cloudfoundry | cf-release | * |
In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cloudfoundry | cf-release | 273 |
| pivotal | capi-release | 1.33.0 |
| pivotal | capi-release | 1.41.0 |
| pivotal | capi-release | 1.35.0 |
| pivotal | capi-release | 1.36.0 |
| pivotal | capi-release | 1.34.0 |
| pivotal | capi-release | 1.40.0 |
| pivotal | capi-release | 1.37.0 |
| cloudfoundry | cf-release | 272 |
| cloudfoundry | cf-release | 268 |
| cloudfoundry | cf-release | 271 |
| pivotal | capi-release | 1.38.0 |
| cloudfoundry | cf-release | 269 |
| pivotal | capi-release | 1.39.0 |
| cloudfoundry | cf-release | 270 |
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID Connect check session iframe endpoint used for single logout session management.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| pivotal | uaa | * |
| pivotal | uaa_bosh | * |
| cloudfoundry | cf-release | * |