HomePivotal SoftwareCVE-2019-11273

CVE-2019-11273

MEDIUM
4.3CVSS
Published: 2019-07-23
Updated: 2024-11-21
AI Analysis

Description

Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may be able to retrieve non-sensitive information.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
low
Integrity
none
Availability
none
Weaknesses
CWE-532CWE-532

Metadata

Primary Vendor
PIVOTAL_SOFTWARE
Published
7/23/2019
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

pivotal_software : pivotal_container_servicepivotal_software : pivotal_container_service

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2019-11273 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com