GoCD是一个持续交付服务器。 GoCD 21.1.0之前版本存在安全漏洞,该漏洞源于GoCD 会将用于加密/解密 GoCD 配置中任何安全变量/秘密的对称密钥泄露给经过身份验证的代理,恶意/受损代理可能会从内存中公开该密钥,攻击者利用该漏洞可以从 GoCD 服务器获得对加密配置值的访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-39311 | 9.1 CRITICAL | Compromised agents may be able to execute remote code on GoCD Server |
| CVE-2022-39308 | 6.5 MEDIUM | GoCD API authentication of user access tokens subject to timing attack during comparison |
| CVE-2022-39310 | 4.9 MEDIUM | Malicious agent may be able to impersonate another agent in GoCD |
No comments yet