PT-2022-19435 · Gocd · Gocd
Published
2022-05-20
·
Updated
2022-06-06
·
CVE-2022-29182
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GoCD versions 19.11.0 through 21.4.0
Description
GoCD is a continuous delivery server that is vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab. This could allow an attacker to steal a GoCD user's session cookies and/or execute malicious code in the user's context by abusing a messaging channel used for communication between the parent page and the stage details graph's iframe.
Recommendations
For GoCD versions 19.11.0 through 21.4.0, update to GoCD 22.1.0 to resolve the issue.
At the moment, there are no known workarounds for this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gocd