-
Notifications
You must be signed in to change notification settings - Fork 972
Security: gocd/gocd
Security Navigation
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
GoCD before 24.5.0 is vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group adminsGHSA-3w9f-fgr5-5g78 published
Jan 3, 2025 by chadlwilsonLow -
GoCD before 24.5.0 is vulnerable to XXE injection via abuse of unused XML configuration repository functionalityGHSA-8xwx-hf68-8xq7 published
Jan 3, 2025 by chadlwilsonLow -
GoCD before 24.5.0 can allow malicious GoCD admins to abuse backup configuration to gain additional host accessGHSA-7jr3-gh3w-vjxq published
Jan 3, 2025 by chadlwilsonLow -
GoCD before 24.5.0 is vulnerable to admin privilege escalation by a malicious internal & authenticated userGHSA-346h-q594-rj8j published
Jan 3, 2025 by chadlwilsonCritical -
GoCD before 24.1.0 has reflected XSS possible while server is restartingGHSA-q882-q6mm-mgvh published
May 12, 2024 by chadlwilsonLow -
GoCD before 23.1.0 has sensitive information disclosure possible on misconfigured failed backups of non-H2 databasesGHSA-p95w-gh78-qjmv published
Mar 27, 2023 by chadlwilsonModerate -
GoCD before 23.1.0 has stored XSS possible on VSM and Job Details pages via malicious pipeline label configurationGHSA-3vvg-gjfr-q9vm published
Mar 27, 2023 by chadlwilsonModerate -
GoCD before 19.11.0 has API authentication of user access tokens subject to timing attack during comparisonGHSA-999p-fp84-jcpq published
Oct 14, 2022 by chadlwilsonModerate -
GoCD before 21.1.0 has server secret encryption/decryption key accidentally leaked to agents during material serializationGHSA-f9qg-xcxq-cgv9 published
Oct 14, 2022 by chadlwilsonModerate -
GoCD before 21.1.0 has malicious agent able to impersonate another agent due to improper access controlGHSA-4fp5-33jh-hgcq published
Oct 14, 2022 by chadlwilsonModerate