CVE-2019-11275: Pivotal Apps Manager
Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.
Affected products
- Pivotal Apps Manager: from 666.0.0, before 666.0.36 (fixed in 666.0.36); from 667.0.0, before 667.0.22 (fixed in 667.0.22); from 668.0.0, before 668.0.21 (fixed in 668.0.21); from 669.0.0, before 669.0.13 (fixed in 669.0.13); from 670.0.0, before 670.0.7 (fixed in 670.0.7)
- Pivotal Software Pivotal Application Service: from 2.3.0, up to and including 2.3.18; from 2.4.0, up to and including 2.4.14; from 2.5.0, up to and including 2.5.1; from 2.6.0, up to and including 2.6.5
Published 2019-10-01. Last modified 2026-06-17.