
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-24832 affects GoCD, an open source continuous delivery server. The vulnerability exists in the bundled gocd-ldap-authentication-plugin included with the GoCD Server versions 17.5.0 through 22.1.0. The plugin fails to correctly escape special characters when using the username to construct LDAP queries (GitHub Advisory, NVD).
The vulnerability stems from improper neutralization of special characters in LDAP queries. When constructing LDAP queries using usernames, the plugin does not properly escape special characters, which can lead to malformed queries. The issue has been assigned a CVSS v3.1 base score of 8.2 HIGH with vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N (GitHub Advisory).
While this vulnerability does not directly allow arbitrary LDAP data exfiltration, it enables an authenticated malicious user to construct and execute crafted queries. This can allow them to deduce information about other users or entries within the LDAP database, including alternate fields, usernames, and hashed passwords through brute force mechanisms. The vulnerability only affects users who have enabled LDAP authorization configuration on their GoCD server (GitHub Advisory).
The vulnerability has been fixed in GoCD version 22.1.0, which includes gocd-ldap-authentication-plugin v2.2.0-144. For users unable to upgrade immediately, several workarounds are available: 1) Remove any authorization configurations for the bundled LDAP Authentication plugin if running outside Docker/Helm 2) Users on GoCD 20.9.0+ can manually upgrade the bundled plugin to v2.2.0-144 3) Consider migrating to the LDAP Authorization Plugin v4.2.0-73+ which supports both authentication and authorization (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."