CVE-2018-1200: Pivotal Software Pivotal Application Service

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links.

Affected products

  • Pivotal Software Pivotal Application Service: from 1.11.0, before 1.11.26 (fixed in 1.11.26); from 1.12.0, before 1.12.14 (fixed in 1.12.14); from 2.0.0, before 2.0.5 (fixed in 2.0.5)

Published 2018-03-16. Last modified 2026-06-17.