GoCD, written in Java, is a popular CI/CD solution with a large range of users from NGOs to Fortune 500 companies with billions of dollars in revenue. Naturally, this makes it a critical piece of infrastructure and an extremely attractive target for attackers. In order to automate build and release processes, a centralized CI/CD solution has access to various production environments and private source code repositories.
A vulnerability that lets unauthenticated attackers leak sensitive information from a vulnerable GoCD Server instance.
- You need to apply related fixes.
- Access restriction should be applied.
Get AI-powered remediation steps tailored to your asset.
Try AI Solutions →