Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/concourse/concourse(Go) | 0 | 5.2.8 | N/A |
| github.com/concourse/concourse(Go) | 5.3.0 | 5.5.10 | N/A |
| github.com/concourse/concourse(Go) | 5.6.0 | 5.8.1 | N/A |
CVSS Metrics