CVE-2019-11275

MEDIUMCVSS 4.3/10EPSS 1.07%

Last modified

CVE-2019-11275 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.

Description

Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.

Metrics

CVSS 3.1
4.3/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS Probability
1.07%

60.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PivotalApps Manager>= 666.0.0, < 666.0.36
PivotalApps Manager>= 667.0.0, < 667.0.22
PivotalApps Manager>= 668.0.0, < 668.0.21
PivotalApps Manager>= 669.0.0, < 669.0.13
PivotalApps Manager>= 670.0.0, < 670.0.7
Pivotal SoftwarePivotal Application Service>= 2.3.0, <= 2.3.18
Pivotal SoftwarePivotal Application Service>= 2.4.0, <= 2.4.14
Pivotal SoftwarePivotal Application Service>= 2.5.0, <= 2.5.1
Pivotal SoftwarePivotal Application Service>= 2.6.0, <= 2.6.5

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-11275?
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.
How severe is CVE-2019-11275?
CVE-2019-11275 has a CVSS score of 4.3/10 (MEDIUM severity). The EPSS model estimates a 1.07% probability of exploitation in the next 30 days.
How do I fix CVE-2019-11275?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-11275?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST