Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.
{
"severity": "HIGH",
"nvd_published_at": null,
"github_reviewed_at": "2021-05-12T18:21:05Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-89"
]
}