concourse vulnerability

Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's credentials. This has been fixed in 8.2.3. No known workarounds are available.

Published 14 Aug 2026Updated 18 Sep 20263 sources
CVSS 0.0

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.