Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown

CVE-2019-12902

Disclosure Date: June 20, 2019 (last updated November 27, 2024)
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.
0
Attacker Value
Unknown

CVE-2019-12903

Disclosure Date: June 20, 2019 (last updated November 27, 2024)
Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information.
0
Attacker Value
Unknown

CVE-2018-1276

Disclosure Date: May 17, 2018 (last updated November 26, 2024)
Windows 2012R2 stemcells, versions prior to 1200.17, contain an information exposure vulnerability on vSphere. A remote user with the ability to push apps can execute crafted commands to read the IaaS metadata from the VM, which may contain BOSH credentials.
0
Attacker Value
Unknown

CVE-2018-1197

Disclosure Date: March 19, 2018 (last updated November 26, 2024)
In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata endpoint. A malicious developer could use this access to gain privileged credentials.
0