GoCD是一个持续交付服务器。 GoCD 19.2.0到19.11.0版本存在安全漏洞,该漏洞源于允许一个经过身份验证的代理冒充另一个代理,从而导致访问控制中断和 GoCD 服务器中代理令牌验证不正确而接收其他代理的工作包,攻击者利用该漏洞可以获取GoCD 服务器敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-39311 | 9.1 CRITICAL | Compromised agents may be able to execute remote code on GoCD Server |
| CVE-2022-39308 | 6.5 MEDIUM | GoCD API authentication of user access tokens subject to timing attack during comparison |
| CVE-2022-39309 | 4.9 MEDIUM | GoCD server secret encryption/decryption key leaked to agents during material serializatio |
No comments yet