Lucene search

K
osvGoogleOSV:GHSA-9689-RX4V-CQGC
HistoryFeb 15, 2022 - 1:57 a.m.

Pivotal Concourse Open Redirect in Login Flow

2022-02-1501:57:18
Google
osv.dev
12
pivotal concourse release
open redirect
login flow
version 4.x
untrusted websites
remote attacker
oauth redirect
access token
concourse
go packages affected
skyserver
software

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

49.6%

Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user’s access token in Concourse.

Specific Go Packages Affected

github.com/concourse/concourse/skymarshal/skyserver

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

49.6%

Related for OSV:GHSA-9689-RX4V-CQGC