CVE-2020-5415
Concourse CI vulnerability analysis and mitigation

Overview

Concourse versions prior to 6.3.1 and 6.4.1, specifically in installations using the GitLab auth connector, were found to be vulnerable to identity spoofing (CVE-2020-5415). The vulnerability was discovered and reported by Gregoire Detrez, with the issue being disclosed on August 11, 2020. The vulnerability affects Concourse installations that utilize the GitLab authentication connector (Tanzu Advisory, NVD).

Technical details

The vulnerability stems from an implementation flaw where the GitLab auth connector uses full names instead of usernames for user identification. This allows attackers to spoof identities by configuring a GitLab account with the same full name as another user who has been granted access to a Concourse team. The vulnerability has been assigned a CVSS v3.1 base score of 10.0 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N (NVD).

Impact

The vulnerability enables identity spoofing attacks where malicious users can impersonate other users by creating GitLab accounts with matching full names. This could lead to unauthorized access to Concourse teams and their resources, potentially compromising the security and integrity of the affected systems (GitHub Advisory).

Exploitability

The vulnerability is exploitable in installations that use the GitLab auth connector for authentication. An attacker only needs to create a GitLab account with a full name matching that of a user who has been granted access to a Concourse team through the team configuration or the --gitlab-user flag (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in Concourse versions 6.3.1 and 6.4.1, released on August 4th, 2020. The fix changes the GitLab connector to use usernames instead of full names for user identification. As a workaround, organizations can move GitLab users into groups and configure the Concourse team to use GitLab groups instead of individual users, as groups are not affected by this vulnerability (GitHub Advisory, Tanzu Advisory).

Additional resources


SourceThis report was generated using AI

Related Concourse CI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-5415CRITICAL10
  • Concourse CI logoConcourse CI
  • cpe:2.3:a:pivotal_software:concourse
NoYesAug 12, 2020
CVE-2019-3792HIGH7.5
  • Concourse CI logoConcourse CI
  • github.com/concourse/concourse
NoYesApr 01, 2019
CVE-2020-5409MEDIUM6.1
  • Concourse CI logoConcourse CI
  • cpe:2.3:a:pivotal_software:concourse
NoYesMay 14, 2020
CVE-2022-31683MEDIUM5.4
  • Concourse CI logoConcourse CI
  • cpe:2.3:a:pivotal_software:concourse
NoYesDec 19, 2022
CVE-2026-49826NONEN/A
  • Concourse CI logoConcourse CI
  • github.com/concourse/concourse
NoYesAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management