Skip to content

v6.7.9

Compare
Choose a tag to compare
@concourse-bot concourse-bot released this 12 Oct 19:34
a96bf82

馃敆 security

  • Fix team name overwritten bug

    • All Concourse versions prior to v6.7.9 is vulnerable to parameter pollution that allows authorization bypass in functionality that is meant to restrict cross team actions. An user in any team could make certain http requests to trigger unauthorized activity for other teams like pausing pipelines, re-triggering builds or exposing pipelines. (#8581)
  • Bump Dex to v2.35.1 for CVE-2022-39222. (#8582)

馃摝 Bundled resource types