GoCD是一个持续交付服务器。 GoCD 19.2.0到19.11.0版本存在安全漏洞,该漏洞源于为代理通信公开的 Spring RemoteInvocation 端点允许对任意 java 对象进行反序列化,攻击者利用该漏洞可以通过受损代理在服务器上执行远程代码攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-39308 | 6.5 MEDIUM | GoCD API authentication of user access tokens subject to timing attack during comparison |
| CVE-2022-39309 | 4.9 MEDIUM | GoCD server secret encryption/decryption key leaked to agents during material serializatio |
| CVE-2022-39310 | 4.9 MEDIUM | Malicious agent may be able to impersonate another agent in GoCD |
No comments yet