Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13560
HistoryMar 28, 2019 - 2:41 a.m.

SQL Injection

2019-03-2802:41:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

EPSS

0.001

Percentile

47.2%

github.com/concourse/concourse is vulnerable to SQL injection. The API does not validate and sanitize user input to the version identifier parameter, allowing a remote attacker inject and execute arbitrary SQL statements to retrieve privileged data from the database.

EPSS

0.001

Percentile

47.2%

Related for VERACODE:13560