Vulnerability Description
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Concourse | >= 6.0.0, < 6.7.9 |
Related Weaknesses (CWE)
References
- https://github.com/concourse/concourse/security/advisories/GHSA-5jp2-vwrj-99rfExploitThird Party Advisory
- https://github.com/concourse/concourse/security/advisories/GHSA-5jp2-vwrj-99rfExploitThird Party Advisory
FAQ
What is CVE-2022-31683?
CVE-2022-31683 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to...
How severe is CVE-2022-31683?
CVE-2022-31683 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31683?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Concourse.