HIGH🇵🇱 Wersja polska

CVE-2018-15798

CVSS 7.6v3.0pub. 2018-12-19upd. 2024-11-21

Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
  • Pivotal Software Concourse

    APP
    Pivotal Software
    4.0.0 – 4.2.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2020-5415CRITICAL10.0PL ✓same product

Concourse GitLab Auth: identity spoofing przez podszywanie się pod użytkownika

CVE-2018-1227HIGH7.5same product

Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer o...

CVE-2022-31683MEDIUM5.4same product

Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse ...

CVE-2020-5409MEDIUM6.1same product

Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A r...

CVE-2019-3792MEDIUM6.8same product

Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource ca...