CyberSec.Space Logo
Back to CVE Browser

CVE-2020-5409

MEDIUM
6.1
CVSS Severity Score
EPSS Score0.0130%
EPSS Percentile6.66th
PublishedMay 14, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access token in Concourse. (This issue is similar to, but distinct from, CVE-2018-15798.)

Affected Platforms (CPE)

📦
Pivotal Software

Concourse

< 5.2.8
📦
Pivotal Software

Concourse

>= 5.3.0 and < 5.5.10
📦
Pivotal Software

Concourse

>= 5.6.0 and < 5.8.1

References & Advisories

Related Vulnerabilities