CVE-2020-5409: Concourse Open Redirect in the /sky/login endpoint
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access token in Concourse. (This issue is similar to, but distinct from, CVE-2018-15798.)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5409?
CVE-2020-5409 is a vulnerability in Pivotal Concourse that allows redirects to untrusted websites in its login flow.
How does CVE-2020-5409 impact Pivotal Concourse?
CVE-2020-5409 allows a remote, unauthenticated attacker to gain access to a user's access token in Concourse by convincing the user to click on a link leading to an untrusted website through the OAuth redirect link.
What is the severity of CVE-2020-5409?
CVE-2020-5409 has a severity keyword of 'high' and a severity value of 6.1.
Which versions of Pivotal Concourse are affected by CVE-2020-5409?
Pivotal Concourse versions prior to 6.0.0 are affected by CVE-2020-5409.
How can CVE-2020-5409 be fixed?
To fix CVE-2020-5409, it is recommended to upgrade to Pivotal Concourse version 6.0.0 or later.