Loading
Generated remediation guidance and an executive summary. No account required.
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access token in Concourse. (This issue is similar to, but distinct from, CVE-2018-15798.)
Use CWE-601, Pivotal Software vendor hub and Concourse product page to widen CVE-2020-5409 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-5415, CVE-2018-15798 and CVE-2018-1227 for nearby disclosures in the same product family.