CVE-2018-15798: Pivotal Concourse allows malicious redirect urls on login
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15798?
CVE-2018-15798 is a vulnerability in Pivotal Concourse Release versions 4.x prior to 4.2.2 that allows redirects to untrusted websites.
How can an attacker exploit CVE-2018-15798?
An attacker can exploit CVE-2018-15798 by convincing a user to click on a link that redirects them to an untrusted website, allowing the attacker to gain access to the user's access token in Concourse.
What is the severity of CVE-2018-15798?
CVE-2018-15798 has a severity rating of 5.4 (High).
Which versions of Pivotal Concourse Release are affected by CVE-2018-15798?
Versions 4.x prior to 4.2.2 are affected by CVE-2018-15798.
How can I fix CVE-2018-15798?
To fix CVE-2018-15798, upgrade to Pivotal Concourse Release version 5.2.8 or higher.