This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: A critical info leak & RCE in GoCD. ๐ **Consequences**: Attackers can execute arbitrary code and steal secrets/keys via command injection in Git URL testing. ๐ฅ
Q2Root Cause? (CWE/Flaw)
๐ก๏ธ **Root Cause**: Command Injection. ๐ **Flaw**: The Git URL 'Test Connection' feature fails to sanitize inputs, allowing malicious commands to run on the server. โ ๏ธ
Q3Who is affected? (Versions/Components)
๐ฏ **Affected**: ThoughtWorks GoCD. ๐ **Versions**: All versions **prior to 21.3.0**. ๐ฆ **Component**: CI/CD Server pipeline creation module. ๐
โ๏ธ **Threshold**: Medium. ๐ **Auth**: Requires ability to **create new pipelines** on the server. ๐ช **Config**: No unauthenticated access needed; needs basic pipeline creation rights. ๐
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ฃ **Public Exp**: YES. ๐ **PoC/EXP**: Available on GitHub (Wrin9) and Nuclei templates. ๐ **Status**: Active exploitation tools exist for file read and command execution. ๐ป
Q7How to self-check? (Features/Scanning)
๐ **Self-Check**: Use Nuclei templates or PoC scripts. ๐ก **Scan**: Target the Git URL 'Test Connection' endpoint. ๐งช **Verify**: Check for command output or file content leakage. ๐
Q8Is it fixed officially? (Patch/Mitigation)
โ **Fixed**: YES. ๐ ๏ธ **Patch**: Upgrade to **GoCD 21.3.0** or later. ๐ฅ **Source**: Official release notes and GitHub commits confirm the fix. ๐
Q9What if no patch? (Workaround)
๐ง **No Patch?**: Restrict pipeline creation permissions. ๐ซ **Mitigation**: Block external Git URL testing or isolate the server. ๐ก๏ธ **Action**: Limit network access to GoCD admin interfaces. ๐
Q10Is it urgent? (Priority Suggestion)
๐ฅ **Urgency**: HIGH. ๐จ **Priority**: Critical. โก **Reason**: Easy to exploit, leads to full server compromise & data theft. ๐ **Action**: Patch immediately! ๐โโ๏ธ