SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-11044

A malicious authenticated user can inject content into an invite to another user, exploiting the trust implied by the source of the email.

MEDIUM 6.5EPSS 0.73%

Does this matter?

Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.

Description

Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when sending invitation emails. A malicious authenticated user can inject content into an invite to another user, exploiting the trust implied by the source of the email.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.73% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
pivotal software/pivotal application service
Source
security_alert@emc.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.