Описание
Pivotal Concourse Open Redirect in Login Flow
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.
Specific Go Packages Affected
github.com/concourse/concourse/skymarshal/skyserver
Пакеты
github.com/concourse/concourse
< 5.2.8
5.2.8
github.com/concourse/concourse
>= 5.3.0, < 5.5.10
5.5.10
github.com/concourse/concourse
>= 5.6.0, < 5.8.1
5.8.1
Связанные уязвимости
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.