CVE-2018-1278
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be discovered. Accepting this invitation gives unauthorized access to view the member list, domains, quotas and other information about the org.
Apps Manager en Pivotal Application Service, en versiones 1.12.x anteriores a la 1.12.22, versiones 2.0.x anteriores a la 2.0.13 y versiones 2.1.x anteriores a la 2.1.4, contiene una vulnerabilidad de imposición de autorización. Un miembro de cualquier org puede crear invitaciones a cualquier org para la cual se puede descubrir la GUID de esta. Si se acepta esta invitación, se otorga acceso no autorizado para ver la lista de miembros, dominios, cuotas y otro tipo de información sobre la org.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-06 CVE Reserved
- 2018-05-11 CVE Published
- 2023-10-02 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104227 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://pivotal.io/security/cve-2018-1278 | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pivotal Software Search vendor "Pivotal Software" | Pivotal Application Service Search vendor "Pivotal Software" for product "Pivotal Application Service" | >= 1.12.0 < 1.12.22 Search vendor "Pivotal Software" for product "Pivotal Application Service" and version " >= 1.12.0 < 1.12.22" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Pivotal Application Service Search vendor "Pivotal Software" for product "Pivotal Application Service" | >= 2.0.0 < 2.0.13 Search vendor "Pivotal Software" for product "Pivotal Application Service" and version " >= 2.0.0 < 2.0.13" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Pivotal Application Service Search vendor "Pivotal Software" for product "Pivotal Application Service" | >= 2.1.0 < 2.1.4 Search vendor "Pivotal Software" for product "Pivotal Application Service" and version " >= 2.1.0 < 2.1.4" | - |
Affected
|