VYPR

Concourse

by Cloudfoundry

Source repositories

CVEs (7)

  • CVE-2020-5415CriAug 12, 2020
    risk 0.65cvss 10.0epss 0.01

    Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team. GitLab groups do not…

  • CVE-2018-1227HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a DNS domain that is no longer controlled by Pivotal. The original domain for the Concourse CI (concourse-dot-ci) open source project…

  • CVE-2018-15798HigDec 19, 2018
    risk 0.42cvss 7.6epss 0.01

    Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access…

  • CVE-2020-5409MedMay 14, 2020
    risk 0.40cvss 6.1epss 0.01

    Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access…

  • CVE-2019-3792MedApr 1, 2019
    risk 0.37cvss 6.8epss 0.01

    Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.

  • CVE-2019-3803MedJan 12, 2019
    risk 0.29cvss 4.5epss 0.01

    Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authenticate as the user.

  • CVE-2022-31683MedDec 19, 2022
    risk 0.28cvss 5.4epss 0.00

    Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team.