PT-2022-24892 · Gocd · Gocd
Published
2022-10-14
·
Updated
2022-10-19
·
CVE-2022-39310
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GoCD versions prior to 21.1.0
Description
The issue allows one authenticated agent to impersonate another agent due to broken access control and incorrect validation of agent tokens within the GoCD server. This can cause accidental information disclosure, as work packages can contain sensitive information such as credentials intended only for a given job running against a specific agent environment. Exploitation requires knowledge of agent identifiers and the ability to authenticate as an existing agent with the GoCD server.
Recommendations
For GoCD versions prior to 21.1.0, update to version 21.1.0 to resolve the issue.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gocd