CVE-2018-1278 is an authorization enforcement vulnerability affecting Pivotal Application Service (PAS) versions 1.12.x, 2.0.x, and 2.1.x. An attacker, if they are a member of any organization and can discover an organization's GUID, can create invitations to that organization. Accepting such an invitation grants unauthorized access to sensitive organizational data, including member lists, domains, and quotas. This vulnerability has a CVSS v3 score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and resulting in high confidentiality impact. There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.12.0, < 1.12.22CPE matchmatch criteria | cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.0.13CPE matchmatch criteria | cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:* | ||
>= 2.1.0, < 2.1.4CPE matchmatch criteria | cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.