Loading HuntDB...

GHSA-67rq-xjmx-ww89

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user could listen to network traffic and gain access to the authorization credentials used to make the invitation requests.

Related CVEs

Key Information

GHSA ID
GHSA-67rq-xjmx-ww89
Published
May 24, 2022 4:44 PM
Last Modified
April 4, 2024 12:05 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 5, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.