CVSS
0.0
CVSS v4.0
EPSS
N/A
Exploit Prediction Score
Published
August 14, 2026
Exploitability
No EPSS data available
Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's credentials. This has been fixed in 8.2.3. No known workarounds are available.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).