Lucene search

K
osvGoogleOSV:CVE-2020-5409
HistoryMay 14, 2020 - 12:15 a.m.

CVE-2020-5409

2020-05-1400:15:11
Google
osv.dev
5

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

49.6%

Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user’s access token in Concourse. (This issue is similar to, but distinct from, CVE-2018-15798.)

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

49.6%

Related for OSV:CVE-2020-5409