Loading
Generated remediation guidance and an executive summary. No account required.
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.
Use CWE-89, Pivotal Software vendor hub and Concourse product page to widen CVE-2019-3792 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-5415, CVE-2018-15798 and CVE-2018-1227 for nearby disclosures in the same product family.