CVE-2019-11275: CSV Injection in usage report downloaded from Pivotal Application Manager
Severity
Low
Vendor
Pivotal
Description
Pivotal Apps Manager, included in Pivotal Application Service versions 2.6.x prior to 2.6.5, 2.5.x prior to 2.5.1, 2.4.x prior to 2.4.14 and 2.3.x prior to 2.3.18 contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.
Affected VMware Products and Versions
Severity is low unless otherwise noted.
-
Apps Manager
- 670 versions prior to 670.0.7
- 669 versions prior to 669.0.13
- 668 versions prior to 668.0.21
- 667 versions prior to 667.0.22
- 666 versions prior to 666.0.36
-
Pivotal Application Service (PAS)
- 2.6 versions prior to 2.6.5
- 2.4 versions prior to 2.4.14
- 2.5 versions prior to 2.5.1
- 2.3 versions prior to 2.3.18
Mitigation
Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:
-
Apps Manager
- 670.0.7
- 669.0.13
- 668.0.21
- 667.0.22
- 666.0.36
-
Pivotal Application Service (PAS)
- 2.6.5
- 2.4.14
- 2.5.1
- 2.3.18
Credit
This issue was responsibly reported by Michael Eder - HvS-Consulting AG.
References
History
2019-09-25: Initial vulnerability report published.