Medium severity6.8NVD Advisory· Published Apr 1, 2019· Updated Jun 17, 2026
CVE-2019-3792
CVE-2019-3792
Description
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/concourse/concourseGo | < 5.0.1 | 5.0.1 |
Affected products
2- Pivotal/Concoursev5Range: All
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-4fqx-74rv-638wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-3792ghsaADVISORY
- pivotal.io/security/cve-2019-3792nvdVendor AdvisoryWEB
- github.com/concourse/concourse/blob/master/release-notes/v5.0.1.mdghsaWEB
- github.com/concourse/concourse/commit/dc3d15ab6c3a69890c9985f9c875d4c2949be727ghsaWEB
News mentions
0No linked articles in our index yet.