CVE-2018-15798
19.12.2018, 22:29
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.
Vendor | Product | Version |
---|---|---|
pivotal_software | concourse | 4.0.0 ≤ 𝑥 < 4.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration