Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team.
2022-12-19T16:15:11.027
2025-04-16T14:15:21.257
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pivotal_software | concourse | < 6.7.9 | Yes |
Application | pivotal_software | concourse | < 7.8.3 | Yes |