Beveiligingsadvies

CVE-2020-5409

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-05-13 23:15:17
Laatst bijgewerkt 2024-09-17 02:47:32
Toegewezen door pivotal
CVSS-score 7.6
Status PUBLISHED

Beschrijving

Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access token in Concourse. (This issue is similar to, but distinct from, CVE-2018-15798.)