PT-2025-1144 · Gocd · Gocd

Baiyecha404

·

Published

2025-01-03

·

Updated

2025-08-01

·

CVE-2024-56324

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions GoCD versions prior to 24.4.0
Description The issue is related to the incorrect restriction of XML external entity references in GoCD, a continuous delivery server. This can allow "group admins" to abuse the ability to edit raw XML configurations, potentially leading to XML External Entity (XXE) injection attacks on the GoCD server. Theoretically, this could result in additional attacks such as Server-Side Request Forgery (SSRF), information disclosure, and directory traversal. However, these additional attacks have not been explicitly demonstrated as exploitable.
Recommendations For versions prior to 24.4.0, consider updating to version 24.5.0 or later, which includes the fix for this issue. As a temporary workaround, consider blocking access to /go/*/pipelines/snippet routes from an external reverse proxy or WAF if "group admin" users do not need the functionality to edit the XML of pipelines directly. Additionally, consider preventing external access from the GoCD server to arbitrary locations using environment egress control.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2025-00423
CVE-2024-56324
GHSA-3W9F-FGR5-5G78

Affected Products

Gocd