CVE-2020-5409
14.05.2020, 00:15
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access token in Concourse. (This issue is similar to, but distinct from, CVE-2018-15798.)
Vendor | Product | Version |
---|---|---|
pivotal_software | concourse | 𝑥 < 5.2.8 |
pivotal_software | concourse | 5.3.0 ≤ 𝑥 < 5.5.10 |
pivotal_software | concourse | 5.6.0 ≤ 𝑥 < 5.8.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration