Known vulnerabilities in Pivotal Concourse

Vendor: Broadcom
Software CPE: cpe:2.3:a:broadcom:concourse:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Pivotal Concourse Pivotal Concourse is affected by 12 known vulnerabilities: 2 high, 3 medium, 7 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144318 - Improper Access Control
CWE-284 Low
No
No
8.3.0 19.08.2026 SB2026081977
#VU144317 - Improper Access Control
CWE-284 Low
No
No
8.3.0 19.08.2026 SB2026081977
#VU144316 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 Low
No
No
8.2.5 19.08.2026 SB2026081976
#VU144315 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-49826
CWE-601 Low
No
No
8.2.3 19.08.2026 SB2026081975
#VU144314 - Improper Access Control
CVE-2022-31683
CWE-284 Low
No
No
6.7.9, 7.8.3 19.10.2022 SB2022101340
#VU68302 - Exposure of sensitive information to an unauthorized actor
CVE-2022-39222
CWE-200 Medium
No
No
6.7.9, 7.8.3 13.10.2022 SB2022101339
SB2022101340
SB2023121205
#VU45747 - Improper Authentication
CVE-2020-5415
CWE-287 Medium
No
No
6.3.1, 6.4.1 17.08.2020 SB2020081711
#VU30287 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2020-5409
CWE-601 Low
No
No
5.8.1 14.05.2020 SB2020051429
#VU26353 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-15798
CWE-601 Low
No
No
4.2.2, 5.2.8, 5.5.10, 5.8.1 24.03.2020 SB2020032417
#VU23556 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-19604
CWE-78 High
No
No
5.2.6, 5.5.7 12.12.2019 SB2019121207
SB2019121209
SB2019121215
and 8 more
#VU18259 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-3792
CWE-89 High
No
No
5.0.1 15.04.2019 SB2019040108
#VU31168 - Exposure of sensitive information to an unauthorized actor
CVE-2019-3803
CWE-200 Medium
No
No
4.2.2 12.01.2019 SB2019011201