Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

gocd — Vulnerabilities & Security Advisories 26

Browse all 26 CVE security advisories affecting gocd. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GoCD is an open-source continuous delivery platform used for automating software builds, tests, and deployments. Historically, it has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The platform's web interface and API have been common attack vectors, with several CVEs allowing unauthorized access or code execution. While no major public security incidents have been widely documented, the 16 recorded CVEs highlight consistent security challenges, particularly in authentication and input validation. Organizations using GoCD should maintain current patch levels and implement proper network segmentation to mitigate risks associated with these historically recurring vulnerability patterns.

Top products by gocd: gocd
CVE ID Title CVSS Severity Published
CVE-2026-55632 GoCD is vulnerable to authorization bypass via pipeline structure API — gocd CWE-863 4.3 Medium 2026-09-23
CVE-2026-52744 GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API — gocd CWE-862 5.3 Medium 2026-09-23
CVE-2026-52742 GoCD is vulnerable to historical server configuration API authorization bypass — gocd CWE-863 5.1 Medium 2026-09-21
CVE-2026-55870 GoCD is vulnerable to credential exposure when admins insecurely configure material URLs — gocd CWE-200 2.3 Low 2026-09-21
CVE-2026-55625 GoCD is vulnerable to authorization bypass via material connection test APIs — gocd CWE-639 4.9 Medium 2026-09-21
CVE-2026-52740 GoCD is vulnerable to pipeline template view API authorization bypass — gocd CWE-863 5.3 Medium 2026-09-21
CVE-2026-55060 GoCD is vulnerable to authorization bypass via support process list API — gocd CWE-863 3.7 Low 2026-09-21
CVE-2026-52741 GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages — gocd CWE-80 7.5 High 2026-09-21
CVE-2026-68919 GoCD has stored XSS possible via forged package material comments on Stage/Job/VSM pages — gocd CWE-80 7.0 High 2026-09-21
CVE-2026-52743 GoCD before 26.1.0 is vulnerable to authorization bypass via job status API — gocd CWE-639 4.3 Medium 2026-09-21
CVE-2024-56324 GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins — gocd CWE-611 6.5 - 2025-01-03
CVE-2024-56322 GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionality — gocd CWE-611 6.7 - 2025-01-03
CVE-2024-56321 GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host access — gocd CWE-20 3.8 Low 2025-01-03
CVE-2024-56320 GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user — gocd CWE-285 8.8 - 2025-01-03
CVE-2024-28866 GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-up — gocd CWE-79 3.1 Low 2024-05-13
CVE-2023-28629 Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocd — gocd CWE-79 5.4 Medium 2023-03-27
CVE-2023-28630 Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocd — gocd CWE-532 4.2 Medium 2023-03-27
CVE-2022-39311 Compromised agents may be able to execute remote code on GoCD Server — gocd CWE-502 9.1 Critical 2022-10-14
CVE-2022-39310 Malicious agent may be able to impersonate another agent in GoCD — gocd CWE-284 4.9 Medium 2022-10-14
CVE-2022-39309 GoCD server secret encryption/decryption key leaked to agents during material serialization — gocd CWE-200 4.9 Medium 2022-10-14
CVE-2022-39308 GoCD API authentication of user access tokens subject to timing attack during comparison — gocd CWE-208 6.5 Medium 2022-10-14
CVE-2022-36088 GoCD Windows installations outside default location inadequately restrict installation file permissions — gocd CWE-284 5.0 Medium 2022-09-07
CVE-2022-29184 Command Injection/Argument Injection in GoCD — gocd CWE-77 8.8 High 2022-05-20
CVE-2022-29183 Reflected XSS in GoCD — gocd CWE-79 4.3 Medium 2022-05-20
CVE-2022-29182 DOM-based XSS in GoCD — gocd CWE-79 4.3 Medium 2022-05-20
CVE-2022-24832 Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames — gocd CWE-74 8.2 High 2022-04-11

This page lists every published CVE security advisory associated with gocd. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.