<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:45:54.581875+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-concourse-2020-5415</id>
    <title>BIT-concourse-2020-5415 — Concourse's GitLab auth allows impersonation</title>
    <updated>2026-10-03T21:45:54.660233+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: concourse</p>
<p>Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team. GitLab groups do not have this vulnerability, so GitLab users may be moved into groups which are then configured in the Concourse team.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-concourse-2020-5415"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-166785</id>
    <title>EUVD-2026-166785</title>
    <updated>2026-10-03T21:45:54.660285+00:00</updated>
    <content>EUVD-2026-166785</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-166785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-5415</id>
    <title>fkie_cve-2020-5415</title>
    <updated>2026-10-03T21:45:54.660302+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team. GitLab groups do not have this vulnerability, so GitLab users may be moved into groups which are then configured in the Concourse team.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-5415"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-627p-rr78-99rj</id>
    <title>GHSA-627p-rr78-99rj — GitLab auth uses full name instead of username as user ID, allowing impersonation</title>
    <updated>2026-10-03T21:45:54.660326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/concourse/concourse, Go: github.com/concourse/dex</p>
<p>### Impact</p>
<p>Installations which use the GitLab auth connector are vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another GitLab user who is granted access to a Concourse team by having their full name listed under `users` in the team configuration or given to the `--gitlab-user` flag.</p>
<p>See the [GitLab auth docs](https://concourse-ci.org/gitlab-auth.html) for details.</p>
<p>Concourse installations which do not configure the GitLab auth connector are not affected.</p>
<p>### Patches</p>
<p>Concourse [v6.3.1](https://github.com/concourse/concourse/releases/tag/v6.3.1) and [v6.4.1](https://github.com/concourse/concourse/releases/tag/v6.4.1) were both released with a fix on August 4th, 2020.</p>
<p>Both versions change the GitLab connector to use the username, rather than the full name. This was always the intent, and the previous behavior was originally reported as a bug (concourse/dex#7) prior to being reported as a security issue.</p>
<p>Any Concourse teams which configure GitLab users will have to switch each user from their full name to their username upon upgrading to these versions.</p>
<p>### Workarounds</p>
<p>GitLab groups do not have this vulnerability, so GitLab users may be moved into groups which are then configured in the Concourse team.</p>
<p>### References</p>
<p>* concourse/dex#12: PR with the fix</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory, you may reach us privately at [concourseteam+security@gmail.com](mailto:concourset…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-627p-rr78-99rj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-5415</id>
    <title>gsd-2020-5415</title>
    <updated>2026-10-03T21:45:54.660384+00:00</updated>
    <content>gsd-2020-5415</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-5415"/>
  </entry>
</feed>
