Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-89"
],
"github_reviewed_at": "2021-05-12T18:21:05Z",
"nvd_published_at": null,
"severity": "HIGH"
}