CVE-2019-3792: Concourse 5.0.0 SQL Injection vulnerability
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3792?
The severity of CVE-2019-3792 is high with a severity value of 7.5.
How does Pivotal Concourse version 5.0.0 become vulnerable to SQL injection?
Pivotal Concourse version 5.0.0 becomes vulnerable to SQL injection due to an API that allows a crafted version identifier to carry a SQL injection payload.
Which version of Pivotal Concourse fixes CVE-2019-3792?
Pivotal Concourse version 5.0.1 fixes CVE-2019-3792.
What can an attacker do with CVE-2019-3792 vulnerability?
An attacker exploiting CVE-2019-3792 can read privileged data on the Concourse server.
Where can I find more information about CVE-2019-3792?
More information about CVE-2019-3792 can be found at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-3792), [GitHub commit](https://github.com/concourse/concourse/commit/dc3d15ab6c3a69890c9985f9c875d4c2949be727), [Release Notes](https://github.com/concourse/concourse/blob/master/release-notes/v5.0.1.md#v501-note-1).