VulnerabilityModified
CVE-2018-11044
A malicious authenticated user can inject content into an invite to another user, exploiting the trust implied by the source of the email.
MEDIUM 6.5EPSS 0.73%
Does this matter?
Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.
Description
Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when sending invitation emails. A malicious authenticated user can inject content into an invite to another user, exploiting the trust implied by the source of the email.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- pivotal software/pivotal application service
- Source
- security_alert@emc.com
References
- https://pivotal.io/security/cve-2018-11044Mitigation, Vendor Advisory
- https://pivotal.io/security/cve-2018-11044Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.