Description
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7028 | Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team. |
Github GHSA |
GHSA-5jp2-vwrj-99rf | Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution |
References
History
Wed, 16 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-04-16T13:57:09.574Z
Reserved: 2022-05-25T00:00:00.000Z
Link: CVE-2022-31683
Updated: 2024-08-03T07:26:01.021Z
Status : Modified
Published: 2022-12-19T16:15:11.027
Modified: 2025-04-16T14:15:21.257
Link: CVE-2022-31683
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA