All Vulnerability Reports

CVE-2019-11275: CSV Injection in usage report downloaded from Pivotal Application Manager


Severity

Low

Vendor

Pivotal

Description

Pivotal Apps Manager, included in Pivotal Application Service versions 2.6.x prior to 2.6.5, 2.5.x prior to 2.5.1, 2.4.x prior to 2.4.14 and 2.3.x prior to 2.3.18 contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.

Affected VMware Products and Versions

Severity is low unless otherwise noted.

  • Apps Manager
    • 670 versions prior to 670.0.7
    • 669 versions prior to 669.0.13
    • 668 versions prior to 668.0.21
    • 667 versions prior to 667.0.22
    • 666 versions prior to 666.0.36
  • Pivotal Application Service (PAS)
    • 2.6 versions prior to 2.6.5
    • 2.4 versions prior to 2.4.14
    • 2.5 versions prior to 2.5.1
    • 2.3 versions prior to 2.3.18

Mitigation

Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:

  • Apps Manager
    • 670.0.7
    • 669.0.13
    • 668.0.21
    • 667.0.22
    • 666.0.36
  • Pivotal Application Service (PAS)
    • 2.6.5
    • 2.4.14
    • 2.5.1
    • 2.3.18

Credit

This issue was responsibly reported by Michael Eder - HvS-Consulting AG.

References

History

2019-09-25: Initial vulnerability report published.