← Back

CVE-2020-5415

nvd nist
Published: Aug 12, 2020Modified: Jun 17, 2026

JSON object

Loading...
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.8
Source: NVD

Description

Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team. GitLab groups do not have this vulnerability, so GitLab users may be moved into groups which are then configured in the Concourse team.

Affected (2)

Concourse
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Pivotal Software
Before 6.3.1
From 6.4.0 to 6.4.1

References (4)

Source: security@pivotal.io
PatchThird Party Advisory
Source: security@pivotal.io
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.