« Volver al listado

CVE-2022-31683

Estado: ModificadaMedia (5.4)—

Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-31683",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-31683",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-16T13:55:04.393045Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Concourse",
          "versions": [
            {
              "status": "affected",
              "version": "Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-12-19T16:15:11.027",
  "references": [
    {
      "url": "https://github.com/concourse/concourse/security/advisories/GHSA-5jp2-vwrj-99rf",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://github.com/concourse/concourse/security/advisories/GHSA-5jp2-vwrj-99rf",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team."
    },
    {
      "lang": "es",
      "value": "Concourse (7.xy anterior a 7.8.3 y 6.xy anterior a 6.7.9) contiene un problema de omisión de autorización. Un usuario de Concourse puede enviar una solicitud con un cuerpo que incluya :team_name=team2 para omitir la verificación del alcance del equipo y obtener acceso a ciertos recursos que pertenecen a cualquier otro equipo."
    }
  ],
  "lastModified": "2026-06-17T04:46:03.390",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pivotal_software:concourse:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33F52A70-FA89-4B11-861F-5EB0B80D746B",
              "versionEndExcluding": "6.7.9",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:concourse:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5351D1D-E34C-4A05-964A-5BC461B0331B",
              "versionEndExcluding": "7.8.3",
              "versionStartIncluding": "7.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}