PT-2022-19436 · Gocd · Gocd

Chadlwilson

·

Published

2022-05-20

·

Updated

2022-06-06

·

CVE-2022-29183

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GoCD versions 20.2.0 through 21.4.0
Description GoCD is a continuous delivery server. The issue concerns reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the returned page. This could allow an attacker to trick a victim into executing code, which would allow the attacker to operate on, or gain control over the same resources as the victim had access to.
Recommendations For GoCD versions 20.2.0 through 21.4.0, update to GoCD 21.4.0 to resolve the issue. As a temporary workaround, consider blocking access to "/go/compare/.*" prior to the GoCD Server via a reverse proxy, web application firewall, or equivalent, to prevent use of the pipeline comparison function.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29183
GHSA-3VVQ-Q4QV-X2GF

Affected Products

Gocd