Known Vulnerabilities for Concourse by Pivotal Software
Listed below are 7 of the newest known vulnerabilities associated with "Concourse" by "Pivotal Software".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-31683 json | Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a... | 5.4 - MEDIUM | 2022-12-19 | 2023-08-08 |
| CVE-2020-5415 json | Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity... | 10 - CRITICAL | 2020-08-12 | 2020-08-19 |
| CVE-2020-5409 json | Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthent... | 6.1 - MEDIUM | 2020-05-14 | 2020-05-15 |
| CVE-2019-3803 json | Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker ... | 7.5 - HIGH | 2019-01-12 | 2019-10-09 |
| CVE-2019-3792 json | Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a versi... | 7.5 - HIGH | 2019-04-01 | 2019-04-09 |
| CVE-2018-15798 json | Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthent... | 5.4 - MEDIUM | 2018-12-19 | 2019-10-09 |
| CVE-2018-1227 json | Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Con... | 7.5 - HIGH | 2018-03-13 | 2019-10-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal Software | Concourse | 6.1.0 | |||
| Application | Pivotal Software | Concourse | 5.8.1 | |||
| Application | Pivotal Software | Concourse | 5.8.0 | |||
| Application | Pivotal Software | Concourse | 5.7.2 | |||
| Application | Pivotal Software | Concourse | 5.7.1 | |||
| Application | Pivotal Software | Concourse | 5.7.0 | |||
| Application | Pivotal Software | Concourse | 5.6.0 | |||
| Application | Pivotal Software | Concourse | 5.5.9 | |||
| Application | Pivotal Software | Concourse | 5.5.8 | |||
| Application | Pivotal Software | Concourse | 5.5.7 | |||
| Application | Pivotal Software | Concourse | 5.5.6 | |||
| Application | Pivotal Software | Concourse | 5.5.5 | |||
| Application | Pivotal Software | Concourse | 5.5.4 | |||
| Application | Pivotal Software | Concourse | 5.5.3 | |||
| Application | Pivotal Software | Concourse | 5.5.11 | |||
| Application | Pivotal Software | Concourse | 5.5.10 | |||
| Application | Pivotal Software | Concourse | 5.5.1 | |||
| Application | Pivotal Software | Concourse | 5.5.0 | |||
| Application | Pivotal Software | Concourse | 5.4.1 | |||
| Application | Pivotal Software | Concourse | 5.4.0 |