CVE-2019-11275: CSV Injection in usage report downloaded from Pivotal Application Manager
Low
Pivotal
Pivotal Apps Manager, included in Pivotal Application Service versions 2.6.x prior to 2.6.5, 2.5.x prior to 2.5.1, 2.4.x prior to 2.4.14 and 2.3.x prior to 2.3.18 contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.
Severity is low unless otherwise noted.
-
Apps Manager
- 670 versions prior to 670.0.7
- 669 versions prior to 669.0.13
- 668 versions prior to 668.0.21
- 667 versions prior to 667.0.22
- 666 versions prior to 666.0.36
-
Pivotal Application Service (PAS)
- 2.6 versions prior to 2.6.5
- 2.4 versions prior to 2.4.14
- 2.5 versions prior to 2.5.1
- 2.3 versions prior to 2.3.18
Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:
-
Apps Manager
- 670.0.7
- 669.0.13
- 668.0.21
- 667.0.22
- 666.0.36
-
Pivotal Application Service (PAS)
- 2.6.5
- 2.4.14
- 2.5.1
- 2.3.18
This issue was responsibly reported by Michael Eder - HvS-Consulting AG.
2019-09-25: Initial vulnerability report published.