Security Advisory

CVE-2019-11280

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-09-20 18:35:17
Last updated 2024-09-16 19:20:44
Assigner pivotal
CVSS score 8.8
State PUBLISHED

Description

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote authenticated user can gain additional privileges by inviting themselves to spaces that they should not have access to.