VulnerabilityModified
CVE-2018-1200
Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links.
MEDIUM 6.5EPSS 1.28%
Does this matter?
Lower severity and a low EPSS score (1.28%). Track it; it rarely justifies an emergency change on its own.
Description
Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 1.28% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- pivotal software/pivotal application service
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/103042Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2018-1200Vendor Advisory
- http://www.securityfocus.com/bid/103042Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2018-1200Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.