5.3 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- argocd
- gocd-agent
- argocd-autopilot
- argocd-vault-plugin
- terraform-providers.argoproj-labs_argocd
- @LeSuisse accepted
- @LeSuisse published on GitHub
GoCD is vulnerable to pipeline template view API authorization bypass
GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with nonstandard HTTP method capitalization to retrieve a pipeline template by name without the required view permission and read its configuration. API operations that modify data are not affected, secure variables remain encrypted, and deployments whose reverse proxy rejects non-uppercase HTTP methods are not affected. This issue is fixed in version 26.1.0.
References
-
https://github.com/gocd/gocd/security/advisories/GHSA-9jfm-4f6v-79wh x_refsource_CONFIRM
-
https://github.com/gocd/gocd/releases/tag/26.1.0 x_refsource_MISC
-
https://www.gocd.org/releases/#26-1-0 x_refsource_MISC
Affected products
- ==>= 18.7.0, < 26.1.0
Matching in nixpkgs
pkgs.gocd-server
Continuous delivery server specializing in advanced workflow modeling and visualization
Ignored packages (5)
pkgs.argocd
Declarative continuous deployment for Kubernetes
pkgs.gocd-agent
Continuous delivery server specializing in advanced workflow modeling and visualization
pkgs.argocd-autopilot
ArgoCD Autopilot
pkgs.argocd-vault-plugin
Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets
pkgs.terraform-providers.argoproj-labs_argocd
None
Package maintainers
-
@swarren83 Shawn Warren <shawn.w.warren@gmail.com>
3.7 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- argocd
- gocd-agent
- argocd-autopilot
- argocd-vault-plugin
- terraform-providers.argoproj-labs_argocd
- @LeSuisse accepted
- @LeSuisse published on GitHub
GoCD is vulnerable to authorization bypass via support process list API
GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames, remote material URLs, and internal material paths for materials the user cannot otherwise access. Exploitation depends on unpredictable process timing, and credentials, environment variables, and user-defined secrets remain masked or omitted. This issue is fixed in version 26.1.0.
References
-
https://github.com/gocd/gocd/security/advisories/GHSA-vqjf-7pf8-hgwr x_refsource_CONFIRM
-
https://github.com/gocd/gocd/releases/tag/26.1.0 x_refsource_MISC
-
https://www.gocd.org/releases/#26-1-0 x_refsource_MISC
Affected products
- ==>= 13.1.0, < 26.1.0
Matching in nixpkgs
pkgs.gocd-server
Continuous delivery server specializing in advanced workflow modeling and visualization
Ignored packages (5)
pkgs.argocd
Declarative continuous deployment for Kubernetes
pkgs.gocd-agent
Continuous delivery server specializing in advanced workflow modeling and visualization
pkgs.argocd-autopilot
ArgoCD Autopilot
pkgs.argocd-vault-plugin
Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets
pkgs.terraform-providers.argoproj-labs_argocd
None
Package maintainers
-
@swarren83 Shawn Warren <shawn.w.warren@gmail.com>
5.1 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): Low (L)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Low (L)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- argocd
- gocd-agent
- argocd-autopilot
- argocd-vault-plugin
- terraform-providers.argoproj-labs_argocd
- @LeSuisse accepted
- @LeSuisse published on GitHub
GoCD is vulnerable to historical server configuration API authorization bypass
GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for groups they administer. The disclosed configuration can include agent auto-registration keys, webhook invocation keys, encrypted material credentials, and GoCD administrator lists. A malicious pipeline group administrator can use disclosed agent registration data to connect a rogue compatible agent, which can create a higher-complexity path to receiving work or overwriting artifacts associated with other groups. Normal authenticated users are not affected, the endpoint does not modify server configuration, and deployments that restrict pipeline editing to full administrators or configuration repositories are not affected. This issue is fixed in version 26.1.0.
References
-
https://github.com/gocd/gocd/security/advisories/GHSA-7xxx-fv46-vp7h x_refsource_CONFIRM
-
https://github.com/gocd/gocd/pull/14398 x_refsource_MISC
-
https://github.com/gocd/gocd/releases/tag/26.1.0 x_refsource_MISC
-
https://www.gocd.org/releases/#26-1-0 x_refsource_MISC
Affected products
- ==>= 12.3.1, < 26.1.0
Matching in nixpkgs
pkgs.gocd-server
Continuous delivery server specializing in advanced workflow modeling and visualization
Ignored packages (5)
pkgs.argocd
Declarative continuous deployment for Kubernetes
pkgs.gocd-agent
Continuous delivery server specializing in advanced workflow modeling and visualization
pkgs.argocd-autopilot
ArgoCD Autopilot
pkgs.argocd-vault-plugin
Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets
pkgs.terraform-providers.argoproj-labs_argocd
None
Package maintainers
-
@swarren83 Shawn Warren <shawn.w.warren@gmail.com>
4.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- argocd
- gocd-agent
- argocd-autopilot
- argocd-vault-plugin
- terraform-providers.argoproj-labs_argocd
- @LeSuisse accepted
- @LeSuisse published on GitHub
GoCD before 26.1.0 is vulnerable to authorization bypass via job status API
GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can guess job IDs and retrieve status for jobs in pipelines the user cannot otherwise view, including job names, state, progress timestamps, assigned agent IP addresses and UUIDs, and associated stages and pipelines. The response does not expose console output, artifacts, commands, variables, or configuration. This issue is fixed in version 26.1.0.
References
-
https://github.com/gocd/gocd/security/advisories/GHSA-2x6r-h7h3-wqc4 x_refsource_CONFIRM
-
https://github.com/gocd/gocd/releases/tag/26.1.0 x_refsource_MISC
-
https://www.gocd.org/releases/#26-1-0 x_refsource_MISC
Affected products
- ==< 26.1.0
Matching in nixpkgs
pkgs.gocd-server
Continuous delivery server specializing in advanced workflow modeling and visualization
Ignored packages (5)
pkgs.argocd
Declarative continuous deployment for Kubernetes
pkgs.gocd-agent
Continuous delivery server specializing in advanced workflow modeling and visualization
pkgs.argocd-autopilot
ArgoCD Autopilot
pkgs.argocd-vault-plugin
Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets
pkgs.terraform-providers.argoproj-labs_argocd
None
Package maintainers
-
@swarren83 Shawn Warren <shawn.w.warren@gmail.com>
7.5 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Attack Requirement (AT): Present (P)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Passive (P)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Attack Requirement (MAT): Present (P)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Passive (P)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- argocd
- gocd-agent
- argocd-autopilot
- argocd-vault-plugin
- terraform-providers.argoproj-labs_argocd
- @LeSuisse accepted
- @LeSuisse published on GitHub
GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages
GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(.+). An attacker with commit access to a tracked material can place URI or HTML special characters in a matching commit comment, causing stored cross-site scripting when a victim views an affected Compare Pipeline page. Deployments without Tracking Tool integration, without an ID capturing group, or with conservative matchers that cannot match special characters are not affected. Successful exploitation can expose a privileged user session or allow changes using the victim's credentials and privileges. This issue is fixed in version 26.1.0.
References
-
https://github.com/gocd/gocd/security/advisories/GHSA-hj3c-q23m-fxcg x_refsource_CONFIRM
-
https://github.com/gocd/gocd/pull/14356 x_refsource_MISC
-
https://github.com/gocd/gocd/releases/tag/26.1.0 x_refsource_MISC
-
https://www.gocd.org/releases/#26-1-0 x_refsource_MISC
Affected products
- ==>= 18.3.0, < 26.1.0
Matching in nixpkgs
pkgs.gocd-server
Continuous delivery server specializing in advanced workflow modeling and visualization
Ignored packages (5)
pkgs.argocd
Declarative continuous deployment for Kubernetes
pkgs.gocd-agent
Continuous delivery server specializing in advanced workflow modeling and visualization
pkgs.argocd-autopilot
ArgoCD Autopilot
pkgs.argocd-vault-plugin
Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets
pkgs.terraform-providers.argoproj-labs_argocd
None
Package maintainers
-
@swarren83 Shawn Warren <shawn.w.warren@gmail.com>
7.0 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Passive (P)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Passive (P)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- argocd
- gocd-agent
- argocd-autopilot
- argocd-vault-plugin
- terraform-providers.argoproj-labs_argocd
- @LeSuisse accepted
- @LeSuisse published on GitHub
GoCD has stored XSS possible via forged package material comments on Stage/Job/VSM pages
GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage Detail, Job/Build Detail, Value Stream Map, and Pipeline History views. A user with write access to a material tracked by GoCD can store arbitrary HTML or JavaScript in a forged package material comment, which executes in the browser session of a user who later views an affected page. Exploitation requires a victim to view a page that renders the malicious modification, and GoCD does not render every material comment in every view. Successful exploitation can expose a privileged user session or allow changes using the victim's credentials and privileges. This issue is fixed in version 26.1.0.
References
-
https://github.com/gocd/gocd/security/advisories/GHSA-pp5x-wgv2-g37p x_refsource_CONFIRM
-
https://github.com/gocd/gocd/releases/tag/26.1.0 x_refsource_MISC
-
https://www.gocd.org/releases/#26-1-0 x_refsource_MISC
Affected products
- ==>= 13.3.0, < 26.1.0
Matching in nixpkgs
pkgs.gocd-server
Continuous delivery server specializing in advanced workflow modeling and visualization
Ignored packages (5)
pkgs.argocd
Declarative continuous deployment for Kubernetes
pkgs.gocd-agent
Continuous delivery server specializing in advanced workflow modeling and visualization
pkgs.argocd-autopilot
ArgoCD Autopilot
pkgs.argocd-vault-plugin
Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets
pkgs.terraform-providers.argoproj-labs_argocd
None
Package maintainers
-
@swarren83 Shawn Warren <shawn.w.warren@gmail.com>
2.3 LOW
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): Present (P)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): Low (L)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): Present (P)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Low (L)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- argocd
- gocd-agent
- argocd-autopilot
- argocd-vault-plugin
- terraform-providers.argoproj-labs_argocd
- @LeSuisse accepted
- @LeSuisse published on GitHub
GoCD is vulnerable to credential exposure when admins insecurely configure material URLs
GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to regular authenticated users. Although GoCD recommends dedicated username and password fields or secret-management plugins, legacy configuration permits credentials in material URLs, and not every mixed-use API consistently applies URL masking for every material type. An authenticated user with access to an affected pipeline can obtain credentials embedded in its material URL, while dedicated password fields remain encrypted and are not exposed by this issue. This issue is fixed in version 26.1.0.
References
-
https://github.com/gocd/gocd/security/advisories/GHSA-5m25-5j77-c887 x_refsource_CONFIRM
-
https://github.com/gocd/gocd/releases/tag/26.1.0 x_refsource_MISC
-
https://www.gocd.org/releases/#26-1-0 x_refsource_MISC
Affected products
- ==< 26.1.0
Matching in nixpkgs
pkgs.gocd-server
Continuous delivery server specializing in advanced workflow modeling and visualization
Ignored packages (5)
pkgs.argocd
Declarative continuous deployment for Kubernetes
pkgs.gocd-agent
Continuous delivery server specializing in advanced workflow modeling and visualization
pkgs.argocd-autopilot
ArgoCD Autopilot
pkgs.argocd-vault-plugin
Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets
pkgs.terraform-providers.argoproj-labs_argocd
None
Package maintainers
-
@swarren83 Shawn Warren <shawn.w.warren@gmail.com>
4.9 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- argocd
- argocd-autopilot
- argocd-vault-plugin
- terraform-providers.argoproj-labs_argocd
- gocd-agent
- @LeSuisse accepted
- @LeSuisse published on GitHub
GoCD is vulnerable to authorization bypass via material connection test APIs
GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and pipeline-group context without sufficient validation. A pipeline group administrator can invoke Test Connection for source control materials outside the administrator's authorized pipeline group or configuration repository and potentially use credentials from those materials. For GoCD 20.6.0 and later, the test context can also resolve external secrets managed by secret-management plugins, including global reusable secrets with separate permissions. This issue is fixed in version 26.1.0.
References
-
https://github.com/gocd/gocd/security/advisories/GHSA-4557-94j8-5p66 x_refsource_CONFIRM
-
https://github.com/gocd/gocd/releases/tag/26.1.0 x_refsource_MISC
-
https://www.gocd.org/releases/#26-1-0 x_refsource_MISC
Affected products
- ==>= 16.1.0, < 26.1.0
Matching in nixpkgs
pkgs.gocd-server
Continuous delivery server specializing in advanced workflow modeling and visualization
Ignored packages (5)
pkgs.argocd
Declarative continuous deployment for Kubernetes
pkgs.gocd-agent
Continuous delivery server specializing in advanced workflow modeling and visualization
pkgs.argocd-autopilot
ArgoCD Autopilot
pkgs.argocd-vault-plugin
Argo CD plugin to retrieve secrets from Secret Management tools and inject them into Kubernetes secrets
pkgs.terraform-providers.argoproj-labs_argocd
None
Package maintainers
-
@swarren83 Shawn Warren <shawn.w.warren@gmail.com>