PT-2022-19436 · Gocd · Gocd
Chadlwilson
·
Published
2022-05-20
·
Updated
2022-06-06
·
CVE-2022-29183
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GoCD versions 20.2.0 through 21.4.0
Description
GoCD is a continuous delivery server. The issue concerns reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the returned page. This could allow an attacker to trick a victim into executing code, which would allow the attacker to operate on, or gain control over the same resources as the victim had access to.
Recommendations
For GoCD versions 20.2.0 through 21.4.0, update to GoCD 21.4.0 to resolve the issue.
As a temporary workaround, consider blocking access to "/go/compare/.*" prior to the GoCD Server via a reverse proxy, web application firewall, or equivalent, to prevent use of the pipeline comparison function.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gocd