« Back to list

Pivotal Software

Pivotal Software Concourse: vulnerabilities and CVEs

Pivotal Software Concourse has 8 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months1
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-49826None (0)0.53%—Aug 14, 2026
Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site.…
CVE-2022-31683Medium (5.4)0.45%—Dec 19, 2022
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to…
CVE-2020-5415Critical (10)1.2%—Aug 12, 2020
Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who…
CVE-2020-5409Medium (6.1)0.91%—May 14, 2020
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an…
CVE-2019-3792High (7.5)1.1%—Apr 1, 2019
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the…
CVE-2019-3803High (7.5)0.64%—Jan 12, 2019
Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to…
CVE-2018-15798Medium (5.4)1.1%—Dec 19, 2018
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an…
CVE-2018-1227High (7.5)1.2%—Mar 13, 2018
Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a DNS domain that is no longer controlled by Pivotal. The original domain…

Other products by Pivotal Software