CVE-2019-3792 (concourse)

Pivotal Concourse versions prior to 5.0.1, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.
Source: NIST
CVE-2019-3792 (concourse)

Leave a Reply

Your email address will not be published.