CVE-2022-24832
GoCD Server vulnerability analysis and mitigation

Overview

CVE-2022-24832 affects GoCD, an open source continuous delivery server. The vulnerability exists in the bundled gocd-ldap-authentication-plugin included with the GoCD Server versions 17.5.0 through 22.1.0. The plugin fails to correctly escape special characters when using the username to construct LDAP queries (GitHub Advisory, NVD).

Technical details

The vulnerability stems from improper neutralization of special characters in LDAP queries. When constructing LDAP queries using usernames, the plugin does not properly escape special characters, which can lead to malformed queries. The issue has been assigned a CVSS v3.1 base score of 8.2 HIGH with vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N (GitHub Advisory).

Impact

While this vulnerability does not directly allow arbitrary LDAP data exfiltration, it enables an authenticated malicious user to construct and execute crafted queries. This can allow them to deduce information about other users or entries within the LDAP database, including alternate fields, usernames, and hashed passwords through brute force mechanisms. The vulnerability only affects users who have enabled LDAP authorization configuration on their GoCD server (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in GoCD version 22.1.0, which includes gocd-ldap-authentication-plugin v2.2.0-144. For users unable to upgrade immediately, several workarounds are available: 1) Remove any authorization configurations for the bundled LDAP Authentication plugin if running outside Docker/Helm 2) Users on GoCD 20.9.0+ can manually upgrade the bundled plugin to v2.2.0-144 3) Consider migrating to the LDAP Authorization Plugin v4.2.0-73+ which supports both authentication and authorization (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related GoCD Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-56320CRITICAL9.4
  • GoCD Server logoGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025
CVE-2024-28866MEDIUM6.1
  • GoCD Server logoGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesMay 14, 2024
CVE-2024-56321LOW3.8
  • GoCD Server logoGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025
CVE-2024-56324LOW2.1
  • GoCD Server logoGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025
CVE-2024-56322LOW2.1
  • GoCD Server logoGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management