Improper access control in Pivotal Concourse - CVE-2022-31683
Published: October 19, 2022 / Updated: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to bypass team scope authorization.
The vulnerability exists due to improper access control in team scope authorization handling when processing POST or PUT requests with :team_name in the request body. A remote user can send a crafted request to bypass team scope authorization.
The issue involves HTTP parameter pollution.