Loading
Generated remediation guidance and an executive summary. No account required.
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team.
Use CWE-639, Pivotal Software vendor hub and Concourse product page to widen CVE-2022-31683 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-5415, CVE-2018-15798 and CVE-2018-1227 for nearby disclosures in the same product family.