CyberSec.Space Logo
返回 CVE 浏览器

CVE-2020-5409

MEDIUM
6.1
CVSS Severity Score
EPSS Score0.0130%
EPSS Percentile6.66th
Published2020年5月14日
Last Modified2024年11月21日

Vulnerability Description

Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access token in Concourse. (This issue is similar to, but distinct from, CVE-2018-15798.)

Affected Platforms (CPE)

📦
Pivotal Software

Concourse

< 5.2.8
📦
Pivotal Software

Concourse

>= 5.3.0 and < 5.5.10
📦
Pivotal Software

Concourse

>= 5.6.0 and < 5.8.1

References & Advisories

相关漏洞威胁