VYPR

Concourse

by Concourse

Source repositories

CVEs (4)

  • CVE-2020-5415CriAug 12, 2020
    risk 0.65cvss 10.0epss 0.01

    Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team. GitLab groups do not…

  • CVE-2018-1227HigMar 13, 2018
    risk 0.49cvss 7.5epss 0.01

    Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a DNS domain that is no longer controlled by Pivotal. The original domain for the Concourse CI (concourse-dot-ci) open source project…

  • CVE-2022-31683MedDec 19, 2022
    risk 0.28cvss 5.4epss 0.00

    Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team.

  • CVE-2026-49826NonAug 14, 2026
    risk 0.00cvss epss 0.00

    Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's…