CVE-2019-11280

HIGH

Pivotal Application Service < 2.3.18, 2.4.14, 2.5.10, 2.6.5 - Privilege Escalation via Invitations

Title source: llm
STIX 2.1

Description

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote authenticated user can gain additional privileges by inviting themselves to spaces that they should not have access to.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2019-11280

Scores

CVSS v3 8.8
EPSS 0.0145
EPSS Percentile 70.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
pivotal_software/pivotal_application_service 2.3.0 - 2.3.18
Published Sep 20, 2019
Tracked Since Feb 18, 2026