Vulnerability Details CVE-2022-31683
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.5%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2022-31683
-
cpe:2.3:a:pivotal_software:concourse:6.0.0
-
cpe:2.3:a:pivotal_software:concourse:6.1.0
-
cpe:2.3:a:pivotal_software:concourse:6.2.0
-
cpe:2.3:a:pivotal_software:concourse:6.3.0
-
cpe:2.3:a:pivotal_software:concourse:6.3.1
-
cpe:2.3:a:pivotal_software:concourse:6.4.0
-
cpe:2.3:a:pivotal_software:concourse:6.4.1
-
cpe:2.3:a:pivotal_software:concourse:6.5.0
-
cpe:2.3:a:pivotal_software:concourse:6.5.1
-
cpe:2.3:a:pivotal_software:concourse:6.6.0
-
cpe:2.3:a:pivotal_software:concourse:6.7.0
-
cpe:2.3:a:pivotal_software:concourse:6.7.1
-
cpe:2.3:a:pivotal_software:concourse:6.7.2
-
cpe:2.3:a:pivotal_software:concourse:6.7.3
-
cpe:2.3:a:pivotal_software:concourse:6.7.4
-
cpe:2.3:a:pivotal_software:concourse:6.7.5
-
cpe:2.3:a:pivotal_software:concourse:6.7.6
-
cpe:2.3:a:pivotal_software:concourse:6.7.7
-
cpe:2.3:a:pivotal_software:concourse:6.7.8
-
cpe:2.3:a:pivotal_software:concourse:7.0.0
-
cpe:2.3:a:pivotal_software:concourse:7.1.0
-
cpe:2.3:a:pivotal_software:concourse:7.2.0
-
cpe:2.3:a:pivotal_software:concourse:7.3.0
-
cpe:2.3:a:pivotal_software:concourse:7.3.1
-
cpe:2.3:a:pivotal_software:concourse:7.3.2
-
cpe:2.3:a:pivotal_software:concourse:7.4.0
-
cpe:2.3:a:pivotal_software:concourse:7.4.1
-
cpe:2.3:a:pivotal_software:concourse:7.4.2
-
cpe:2.3:a:pivotal_software:concourse:7.4.3
-
cpe:2.3:a:pivotal_software:concourse:7.4.4
-
cpe:2.3:a:pivotal_software:concourse:7.5.0
-
cpe:2.3:a:pivotal_software:concourse:7.6.0
-
cpe:2.3:a:pivotal_software:concourse:7.7.0
-
cpe:2.3:a:pivotal_software:concourse:7.7.1
-
cpe:2.3:a:pivotal_software:concourse:7.8.0
-
cpe:2.3:a:pivotal_software:concourse:7.8.1
-
cpe:2.3:a:pivotal_software:concourse:7.8.2