
Cloud Vulnerability DB
A community-led vulnerabilities database
Concourse versions prior to 6.3.1 and 6.4.1, specifically in installations using the GitLab auth connector, were found to be vulnerable to identity spoofing (CVE-2020-5415). The vulnerability was discovered and reported by Gregoire Detrez, with the issue being disclosed on August 11, 2020. The vulnerability affects Concourse installations that utilize the GitLab authentication connector (Tanzu Advisory, NVD).
The vulnerability stems from an implementation flaw where the GitLab auth connector uses full names instead of usernames for user identification. This allows attackers to spoof identities by configuring a GitLab account with the same full name as another user who has been granted access to a Concourse team. The vulnerability has been assigned a CVSS v3.1 base score of 10.0 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N (NVD).
The vulnerability enables identity spoofing attacks where malicious users can impersonate other users by creating GitLab accounts with matching full names. This could lead to unauthorized access to Concourse teams and their resources, potentially compromising the security and integrity of the affected systems (GitHub Advisory).
The vulnerability is exploitable in installations that use the GitLab auth connector for authentication. An attacker only needs to create a GitLab account with a full name matching that of a user who has been granted access to a Concourse team through the team configuration or the --gitlab-user flag (GitHub Advisory).
The vulnerability has been patched in Concourse versions 6.3.1 and 6.4.1, released on August 4th, 2020. The fix changes the GitLab connector to use usernames instead of full names for user identification. As a workaround, organizations can move GitLab users into groups and configure the Concourse team to use GitLab groups instead of individual users, as groups are not affected by this vulnerability (GitHub Advisory, Tanzu Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."