Page 12 of 57 results (0.003 seconds)

CVSS: 7.5EPSS: 0%CPEs: 13EXPL: 0

Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intended network-connectivity restrictions by leveraging access to the 169.254.169.254 address. Pivotal Cloud Foundry (PCF) Elastic Runtime en versiones anteriores a 1.6.34 y 1.7.x en versiones anteriores a 1.7.12 sitúa 169.254.0.0/16 en el all_open Application Security Group, lo que podría permitir a atacantes remotos eludir las restricciones de conectividad de red mediante el aprovechamiento del acceso a la dirección 169.254.169.254. • http://www.securityfocus.com/bid/92161 https://pivotal.io/security/cve-2016-0896 • CWE-254: 7PK - Security Features •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework. Vulnerabilidad de XSS en Apps Manager en Pivotal Cloud Foundry (PCF) Elastic Runtime en versiones anteriores a 1.6.32 y 1.7.x en versiones anteriores a 1.7.8 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de entrada no especificada que interactúa de manera incorrecta con el marco de referencia AngularJS. • http://www.securityfocus.com/bid/91677 https://pivotal.io/security/cve-2016-0926 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •