CVE-2022-39309
GoCD Server vulnerability analysis and mitigation

Overview

CVE-2022-39309 affects GoCD versions prior to 21.1.0, where the server's symmetric key used for encrypting and decrypting secure variables and secrets in the GoCD configuration was accidentally leaked to authenticated agents. The vulnerability was discovered and disclosed on October 14, 2022 (GitHub Advisory).

Technical details

The vulnerability allows authenticated agents to access the symmetric encryption key used by the GoCD server for securing sensitive configuration data. This occurs during material serialization, where the key is unintentionally exposed in memory. The vulnerability has a CVSS v3.1 base score of 4.9 (Moderate) with the following vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N (GitHub Advisory).

Impact

If exploited, a malicious or compromised agent could extract the encryption key from memory and potentially decrypt any secrets intended for other agents or environments. This is particularly concerning if an attacker can also obtain access to encrypted configuration values from the GoCD server. Users who do not use secret variables or store passwords/credentials for connectivity with external systems/source control servers within the GoCD server configuration are unaffected by this vulnerability (GitHub Advisory).

Mitigation and workarounds

The vulnerability was fixed in GoCD version 21.1.0. No known workarounds exist for affected versions. Users are recommended to upgrade to version 21.1.0 or later to address this security issue (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related GoCD Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-56320CRITICAL9.4
  • GoCD ServerGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025
CVE-2024-28866MEDIUM6.1
  • GoCD ServerGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesMay 14, 2024
CVE-2024-56321LOW3.8
  • GoCD ServerGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025
CVE-2024-56324LOW2.1
  • GoCD ServerGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025
CVE-2024-56322LOW2.1
  • GoCD ServerGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management