Skip to main content

Vendor/product archive

pivotal_software / concourse CVEs

Beta · best-effort

7 CVEs tagged to pivotal_software / concourse1 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2022-31683

Published Dec 19, 2022

Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypas…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5415

Published Aug 12, 2020

Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-5409

Published May 14, 2020

Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a li…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3792

Published Apr 1, 2019

Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3803

Published Jan 12, 2019

Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obt…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15798

Published Dec 19, 2018

Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a li…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1227

Published Mar 13, 2018

Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a DNS domain that is no longer co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1