Lucene search

K
githubGitHub Advisory DatabaseGHSA-9689-RX4V-CQGC
HistoryFeb 15, 2022 - 1:57 a.m.

Pivotal Concourse Open Redirect in Login Flow

2022-02-1501:57:18
CWE-601
GitHub Advisory Database
github.com
6
pivotal concourse release
open redirect
login flow
untrusted websites
remote attacker
access token
concourse
oauth redirect link
user security
go packages affected
skyserver
software

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

EPSS

0.001

Percentile

49.6%

Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user’s access token in Concourse.

Specific Go Packages Affected

github.com/concourse/concourse/skymarshal/skyserver

Affected configurations

Vulners
Node
pivotal_softwareconcourseRange<5.8.1
OR
pivotal_softwareconcourseRange<5.5.10
OR
pivotal_softwareconcourseRange<5.2.8
VendorProductVersionCPE
pivotal_softwareconcourse*cpe:2.3:a:pivotal_software:concourse:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

EPSS

0.001

Percentile

49.6%

Related for GHSA-9689-RX4V-CQGC