Pivotal Concourse Open Redirect in Login Flow
Moderate severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Package
Affected versions
< 5.2.8
>= 5.3.0, < 5.5.10
>= 5.6.0, < 5.8.1
Patched versions
5.2.8
5.5.10
5.8.1
Description
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Oct 2, 2023
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.
Specific Go Packages Affected
github.com/concourse/concourse/skymarshal/skyserver
References