QID 730706
Date Published: 2023-01-24
QID 730706: GoCD Sensitive Data Exposure Vulnerability
GoCD is a continuous delivery server. It helps you automate and streamline the build-test-release cycle for worry-free, continuous delivery of your product.
Affected Versions:
GoCD v17.5.0 prior to v22.1.0
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version via sugar_version.json endpoint.
Note: The vulnerability only affects users who have a working LDAP authorization configuration enabled on their GoCD server, and only is exploitable by users authenticating using such an LDAP configuration. So the detection is marked as practice.
It can allow an existing LDAP-authenticated GoCD user with malicious intent to construct and execute malicious queries.
Solution
Customers are advised to upgrade to GoCD v22.1.0 to remediate these vulnerabilities.
Vendor References
- GHSA-x5v3-x9qj-mh3h -
github.com/gocd/gocd/security/advisories/GHSA-x5v3-x9qj-mh3h
CVEs related to QID 730706
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x5v3-x9qj-mh3h |
|