CVE-2022-31683
19.12.2022, 16:15
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team.Enginsight
Vendor | Product | Version |
---|---|---|
pivotal_software | concourse | 6.0.0 ≤ 𝑥 < 6.7.9 |
pivotal_software | concourse | 7.0.0 ≤ 𝑥 < 7.8.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration