GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage Detail, Job/Build Detai
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-52741 | 7.5 HIGH | GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages |
| CVE-2026-52740 | 5.3 MEDIUM | GoCD is vulnerable to pipeline template view API authorization bypass |
| CVE-2026-52742 | 5.1 MEDIUM | GoCD is vulnerable to historical server configuration API authorization bypass |
| CVE-2026-55625 | 4.9 MEDIUM | GoCD is vulnerable to authorization bypass via material connection test APIs |
| CVE-2026-52743 | 4.3 MEDIUM | GoCD before 26.1.0 is vulnerable to authorization bypass via job status API |
| CVE-2026-55060 | 3.7 LOW | GoCD is vulnerable to authorization bypass via support process list API |
| CVE-2026-55870 | 2.3 LOW | GoCD is vulnerable to credential exposure when admins insecurely configure material URLs |
暂无评论