CVE-2019-11273: Pivotal Software Pivotal Container Service

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may be able to retrieve non-sensitive information.

Affected products

  • Pivotal Software Pivotal Container Service: from 1.3.0, before 1.3.7 (fixed in 1.3.7); from 1.4.0, before 1.4.1 (fixed in 1.4.1)

Published 2019-07-23. Last modified 2026-06-17.