CVE-2022-24832

Summary

CVECVE-2022-24832
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2022-04-11 21:15:00 UTC
Updated2022-04-19 15:25:00 UTC
DescriptionGoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly escape special characters when using the username to construct LDAP queries. While this does not directly allow arbitrary LDAP data exfiltration, it can allow an existing LDAP-authenticated GoCD user with malicious intent to construct and execute malicious queries, allowing them to deduce facts about other users or entries within the LDAP database (e.g alternate fields, usernames, hashed passwords etc) through brute force mechanisms. This only affects users who have a working LDAP authorization configuration enabled on their GoCD server, and only is exploitable by users authenticating using such an LDAP configuration. This issue has been fixed in GoCD 22.1.0, which is bundled with gocd-ldap-authentication-plugin v2.2.0-144.

Risk And Classification

Problem Types: CWE-74

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Thoughtworks Gocd All All All All

References

ReferenceSourceLinkTags
Bump bundled gocd-ldap-authentication-plugin to v2.2.0-144 by chadlwilson · Pull Request #10244 · gocd/gocd · GitHub MISC github.com
GitHub - gocd/gocd-ldap-authentication-plugin: LDAP authentication plugin for GoCD MISC github.com
Escape/encode values when building search filters. · gocd/gocd-ldap-authentication-plugin@87fa7da · GitHub MISC github.com
Authentication | GoCD User Documentation MISC docs.gocd.org
Release GoCD 22.1.0 · gocd/gocd · GitHub MISC github.com
Releases - Version notes | GoCD MISC www.gocd.org
Release 2.2.0-144 · gocd/gocd-ldap-authentication-plugin · GitHub MISC github.com
Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames · Advisory · gocd/gocd · GitHub CONFIRM github.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 730706 GoCD Sensitive Data Exposure Vulnerability

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report