PT-2025-1151 · Gocd · Gocd

Baiyecha404

·

Published

2025-01-03

·

Updated

2025-08-01

·

CVE-2024-56321

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions GoCD versions 18.9.0 through 24.4.0
Description The issue exists due to incorrect restriction of the path name to a directory with limited access. This can allow a remote attacker to execute arbitrary code. Specifically, GoCD admins can abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or container as GoCD's user. The impact of this vulnerability is limited in most configurations, as a user who can log into the GoCD UI as an admin often has host administration permissions. However, in restricted environments where host administration is separated from the role of a GoCD admin, this may be unexpected.
Recommendations For GoCD versions 18.9.0 through 24.4.0, update to version 24.5.0 or later, where post-backup scripts can no longer be executed from within certain sensitive locations on the GoCD server. As a temporary workaround, consider restricting access to the backup configuration "post-backup script" feature to minimize the risk of exploitation. Additionally, restrict the ability of GoCD admins to configure and schedule pipeline tasks on all GoCD agents available to the server, to prevent co-ordinated task execution similar to that of post-backup-scripts.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-00431
CVE-2024-56321
GHSA-7JR3-GH3W-VJXQ

Affected Products

Gocd