Loading
Generated remediation guidance and an executive summary. No account required.
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.
Use CWE-601, Pivotal Software vendor hub and Concourse product page to widen CVE-2018-15798 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-5415, CVE-2018-1227 and CVE-2019-3792 for nearby disclosures in the same product family.