Nixpkgs security tracker

Try the new UI
Login with GitHub

Details of issue NIXPKGS-2026-2699

NIXPKGS-2026-2699
published an hour ago
gocd-server: security issues < 26.1.0
Permalink CVE-2026-52740
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated an hour ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • argocd
    • gocd-agent
    • argocd-autopilot
    • argocd-vault-plugin
    • terraform-providers.argoproj-labs_argocd
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
GoCD is vulnerable to pipeline template view API authorization bypass

GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with nonstandard HTTP method capitalization to retrieve a pipeline template by name without the required view permission and read its configuration. API operations that modify data are not affected, secure variables remain encrypted, and deployments whose reverse proxy rejects non-uppercase HTTP methods are not affected. This issue is fixed in version 26.1.0.

Affected products

gocd
  • ==>= 18.7.0, < 26.1.0

Matching in nixpkgs

pkgs.gocd-server

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.argocd

Declarative continuous deployment for Kubernetes

  • nixos-unstable -
    • nixos-unstable-small 3.4.6
  • nixos-26.05 -
    • nixos-26.05-small 3.3.6

pkgs.gocd-agent

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -

pkgs.argocd-vault-plugin

Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-55060
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated an hour ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • argocd
    • gocd-agent
    • argocd-autopilot
    • argocd-vault-plugin
    • terraform-providers.argoproj-labs_argocd
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
GoCD is vulnerable to authorization bypass via support process list API

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames, remote material URLs, and internal material paths for materials the user cannot otherwise access. Exploitation depends on unpredictable process timing, and credentials, environment variables, and user-defined secrets remain masked or omitted. This issue is fixed in version 26.1.0.

Affected products

gocd
  • ==>= 13.1.0, < 26.1.0

Matching in nixpkgs

pkgs.gocd-server

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.argocd

Declarative continuous deployment for Kubernetes

  • nixos-unstable -
    • nixos-unstable-small 3.4.6
  • nixos-26.05 -
    • nixos-26.05-small 3.3.6

pkgs.gocd-agent

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -

pkgs.argocd-vault-plugin

Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-52742
5.1 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated an hour ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • argocd
    • gocd-agent
    • argocd-autopilot
    • argocd-vault-plugin
    • terraform-providers.argoproj-labs_argocd
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
GoCD is vulnerable to historical server configuration API authorization bypass

GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for groups they administer. The disclosed configuration can include agent auto-registration keys, webhook invocation keys, encrypted material credentials, and GoCD administrator lists. A malicious pipeline group administrator can use disclosed agent registration data to connect a rogue compatible agent, which can create a higher-complexity path to receiving work or overwriting artifacts associated with other groups. Normal authenticated users are not affected, the endpoint does not modify server configuration, and deployments that restrict pipeline editing to full administrators or configuration repositories are not affected. This issue is fixed in version 26.1.0.

Affected products

gocd
  • ==>= 12.3.1, < 26.1.0

Matching in nixpkgs

pkgs.gocd-server

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.argocd

Declarative continuous deployment for Kubernetes

  • nixos-unstable -
    • nixos-unstable-small 3.4.6
  • nixos-26.05 -
    • nixos-26.05-small 3.3.6

pkgs.gocd-agent

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -

pkgs.argocd-vault-plugin

Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-52743
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated an hour ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • argocd
    • gocd-agent
    • argocd-autopilot
    • argocd-vault-plugin
    • terraform-providers.argoproj-labs_argocd
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
GoCD before 26.1.0 is vulnerable to authorization bypass via job status API

GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can guess job IDs and retrieve status for jobs in pipelines the user cannot otherwise view, including job names, state, progress timestamps, assigned agent IP addresses and UUIDs, and associated stages and pipelines. The response does not expose console output, artifacts, commands, variables, or configuration. This issue is fixed in version 26.1.0.

Affected products

gocd
  • ==< 26.1.0

Matching in nixpkgs

pkgs.gocd-server

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.argocd

Declarative continuous deployment for Kubernetes

  • nixos-unstable -
    • nixos-unstable-small 3.4.6
  • nixos-26.05 -
    • nixos-26.05-small 3.3.6

pkgs.gocd-agent

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -

pkgs.argocd-vault-plugin

Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-52741
7.5 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated an hour ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • argocd
    • gocd-agent
    • argocd-autopilot
    • argocd-vault-plugin
    • terraform-providers.argoproj-labs_argocd
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages

GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(.+). An attacker with commit access to a tracked material can place URI or HTML special characters in a matching commit comment, causing stored cross-site scripting when a victim views an affected Compare Pipeline page. Deployments without Tracking Tool integration, without an ID capturing group, or with conservative matchers that cannot match special characters are not affected. Successful exploitation can expose a privileged user session or allow changes using the victim's credentials and privileges. This issue is fixed in version 26.1.0.

Affected products

gocd
  • ==>= 18.3.0, < 26.1.0

Matching in nixpkgs

pkgs.gocd-server

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.argocd

Declarative continuous deployment for Kubernetes

  • nixos-unstable -
    • nixos-unstable-small 3.4.6
  • nixos-26.05 -
    • nixos-26.05-small 3.3.6

pkgs.gocd-agent

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -

pkgs.argocd-vault-plugin

Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-68919
7.0 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated an hour ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • argocd
    • gocd-agent
    • argocd-autopilot
    • argocd-vault-plugin
    • terraform-providers.argoproj-labs_argocd
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
GoCD has stored XSS possible via forged package material comments on Stage/Job/VSM pages

GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage Detail, Job/Build Detail, Value Stream Map, and Pipeline History views. A user with write access to a material tracked by GoCD can store arbitrary HTML or JavaScript in a forged package material comment, which executes in the browser session of a user who later views an affected page. Exploitation requires a victim to view a page that renders the malicious modification, and GoCD does not render every material comment in every view. Successful exploitation can expose a privileged user session or allow changes using the victim's credentials and privileges. This issue is fixed in version 26.1.0.

Affected products

gocd
  • ==>= 13.3.0, < 26.1.0

Matching in nixpkgs

pkgs.gocd-server

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.argocd

Declarative continuous deployment for Kubernetes

  • nixos-unstable -
    • nixos-unstable-small 3.4.6
  • nixos-26.05 -
    • nixos-26.05-small 3.3.6

pkgs.gocd-agent

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -

pkgs.argocd-vault-plugin

Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-55870
2.3 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated an hour ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • argocd
    • gocd-agent
    • argocd-autopilot
    • argocd-vault-plugin
    • terraform-providers.argoproj-labs_argocd
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
GoCD is vulnerable to credential exposure when admins insecurely configure material URLs

GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to regular authenticated users. Although GoCD recommends dedicated username and password fields or secret-management plugins, legacy configuration permits credentials in material URLs, and not every mixed-use API consistently applies URL masking for every material type. An authenticated user with access to an affected pipeline can obtain credentials embedded in its material URL, while dedicated password fields remain encrypted and are not exposed by this issue. This issue is fixed in version 26.1.0.

Affected products

gocd
  • ==< 26.1.0

Matching in nixpkgs

pkgs.gocd-server

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.argocd

Declarative continuous deployment for Kubernetes

  • nixos-unstable -
    • nixos-unstable-small 3.4.6
  • nixos-26.05 -
    • nixos-26.05-small 3.3.6

pkgs.gocd-agent

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -

pkgs.argocd-vault-plugin

Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Permalink CVE-2026-55625
4.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated an hour ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • argocd
    • argocd-autopilot
    • argocd-vault-plugin
    • terraform-providers.argoproj-labs_argocd
    • gocd-agent
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
GoCD is vulnerable to authorization bypass via material connection test APIs

GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and pipeline-group context without sufficient validation. A pipeline group administrator can invoke Test Connection for source control materials outside the administrator's authorized pipeline group or configuration repository and potentially use credentials from those materials. For GoCD 20.6.0 and later, the test context can also resolve external secrets managed by secret-management plugins, including global reusable secrets with separate permissions. This issue is fixed in version 26.1.0.

Affected products

gocd
  • ==>= 16.1.0, < 26.1.0

Matching in nixpkgs

pkgs.gocd-server

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.argocd

Declarative continuous deployment for Kubernetes

  • nixos-unstable -
    • nixos-unstable-small 3.4.6
  • nixos-26.05 -
    • nixos-26.05-small 3.3.6

pkgs.gocd-agent

Continuous delivery server specializing in advanced workflow modeling and visualization

  • nixos-unstable -
  • nixos-26.05 -

pkgs.argocd-vault-plugin

Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers