CVE-2018-1200

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
16/03/2018
Last modified:
10/04/2018

Description

Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:* 1.11.0 (including) 1.11.26 (excluding)
cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:* 1.12.0 (including) 1.12.14 (excluding)
cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.5 (excluding)