Loading HuntDB...

GHSA-4fqx-74rv-638w

GitHub Security Advisory

Pivotal Concourse SQL Injection Vulnerability

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.

Affected Packages

Go github.com/concourse/concourse
Affected versions: 0 (fixed in 5.0.1)

Related CVEs

Key Information

GHSA ID
GHSA-4fqx-74rv-638w
Published
February 15, 2022 1:57 AM
Last Modified
September 15, 2023 6:12 PM
CVSS Score
7.5 /10
Primary Ecosystem
Go
Primary Package
github.com/concourse/concourse
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 5, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.