Vulnerabilities (CVE)

Filtered by vendor Pivotal Software Subscribe
Filtered by product Concourse
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31683 1 Pivotal Software 1 Concourse 2023-08-08 N/A 5.4 MEDIUM
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team.
CVE-2020-5409 1 Pivotal Software 1 Concourse 2020-05-15 5.8 MEDIUM 6.1 MEDIUM
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access token in Concourse. (This issue is similar to, but distinct from, CVE-2018-15798.)
CVE-2018-15798 1 Pivotal Software 1 Concourse 2019-10-09 5.8 MEDIUM 5.4 MEDIUM
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.