v6.7.9
馃敆 security
-
Fix team name overwritten bug
- All Concourse versions prior to v6.7.9 is vulnerable to parameter pollution that allows authorization bypass in functionality that is meant to restrict cross team actions. An user in any team could make certain http requests to trigger unauthorized activity for other teams like pausing pipelines, re-triggering builds or exposing pipelines. (#8581)
-
Bump Dex to v2.35.1 for CVE-2022-39222. (#8582)