Vulnerability Description
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may be able to retrieve non-sensitive information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Pivotal Container Service | >= 1.3.0, < 1.3.7 |
Related Weaknesses (CWE)
References
- https://pivotal.io/security/CVE-2019-11273Vendor Advisory
- https://pivotal.io/security/CVE-2019-11273Vendor Advisory
FAQ
What is CVE-2019-11273?
CVE-2019-11273 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remot...
How severe is CVE-2019-11273?
CVE-2019-11273 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11273?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Pivotal Container Service.