CVE-2019-11275

P

ivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.

References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pivotal:apps_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:pivotal:apps_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:pivotal:apps_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:pivotal:apps_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:pivotal:apps_manager:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:20

Type Values Removed Values Added
References () https://pivotal.io/security/cve-2019-11275 - Vendor Advisory () https://pivotal.io/security/cve-2019-11275 - Vendor Advisory

Information

Published : 2019-10-01 15:15

Updated : 2024-11-21 04:20


NVD link : CVE-2019-11275

Mitre link : CVE-2019-11275

CVE.ORG link : CVE-2019-11275


JSON object : View

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-1236

Improper Neutralization of Formula Elements in a CSV File