GoCD Cruise Configuration disclosure Vulnerability Scanner
There is a Cruise Configuration disclosure vulnerability in GoCD, which allow remote attackers to read sensitive information.
Short Info
Level
High
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
2 months 25 days
Scan only one
URL
Toolbox
-
GoCD, written in Java, is a popular CI/CD solution with a large range of users from NGOs to Fortune 500 companies with billions of dollars in revenue. Naturally, this makes it a critical piece of infrastructure and an extremely attractive target for attackers. In order to automate build and release processes, a centralized CI/CD solution has access to various production environments and private source code repositories.
A vulnerability that lets unauthenticated attackers leak sensitive information from a vulnerable GoCD Server instance.