Back to overview

CVE-2020-5415

CRITICAL
10.0
CVSS 3.0
Description
Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team. GitLab groups do not have this vulnerability, so GitLab users may be moved into groups which are then configured in the Concourse team.

Metadata

CVE ID
CVE-2020-5415
State
PUBLISHED
Assigner
pivotal
Reserved
2020-01-03 00:00 UTC
Published
2020-08-12 16:40 UTC
Last updated
2024-09-16 17:53 UTC
Primary CWE
CWE-290
CWE-290: Authentication Bypass by Spoofing
Vendor / Product
VMware Tanzu / Concourse
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Affected products (1)
VendorProductPlatformVersions
VMware Tanzu Concourse 6.4 < 6.4.1, 6.3 < 6.3.1
Weakness (CWE)
CWESourceDescription
CWE-290 cna CWE-290: Authentication Bypass by Spoofing
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Back to overview