Loading HuntDB...

GHSA-wcww-4vrg-9h35

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be discovered. Accepting this invitation gives unauthorized access to view the member list, domains, quotas and other information about the org.

Related CVEs

Key Information

GHSA ID
GHSA-wcww-4vrg-9h35
Published
May 13, 2022 1:49 AM
Last Modified
May 13, 2022 1:49 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.