CVE-2024-56324
GoCD Server vulnerability analysis and mitigation

Overview

GoCD is a continuous delivery server. In versions prior to 24.4.0, GoCD "group admins" could abuse their ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. The vulnerability was discovered in January 2025 and was fixed in GoCD version 24.5.0 (GitHub Advisory).

Technical details

The vulnerability is classified as an XML External Entity (XXE) injection vulnerability (CWE-611). The issue has a CVSS v4.0 base score of 2.1 (Low) with the vector string CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. The vulnerability could theoretically result in additional attacks such as SSRF, information disclosure from the GoCD server, and directory traversal, although these additional attacks have not been explicitly demonstrated as exploitable (GitHub Advisory).

Impact

The vulnerability allows group administrators to potentially access sensitive information from the GoCD server through XXE injection. While the direct impact is limited to information disclosure, the vulnerability could theoretically enable Server-Side Request Forgery (SSRF) and directory traversal attacks, though these have not been proven exploitable (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in GoCD version 24.5.0. For users unable to upgrade immediately, two workarounds are available: 1) Temporarily block access to /go/*/pipelines/snippet routes from an external reverse proxy or WAF if group admin users don't need the functionality to edit XML of pipelines directly, or 2) Prevent external access from the GoCD server to arbitrary locations using environment egress control (GitHub Advisory, GoCD Release).

Additional resources


SourceThis report was generated using AI

Related GoCD Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-56320CRITICAL9.4
  • GoCD Server logoGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025
CVE-2024-28866MEDIUM6.1
  • GoCD Server logoGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesMay 14, 2024
CVE-2024-56321LOW3.8
  • GoCD Server logoGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025
CVE-2024-56324LOW2.1
  • GoCD Server logoGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025
CVE-2024-56322LOW2.1
  • GoCD Server logoGoCD Server
  • cpe:2.3:a:thoughtworks:gocd
NoYesJan 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management