Skip to content

H3-2022-0029

Unauthenticated Access to ThoughtWorks GoCD

Category SECURITY_MISCONFIGURATION
Base Score 9.8

Description

An authentication bypass was found in GoCD that allows the attacker to abuse certain critical endpoints.

Impact

An unauthenticated attacker can abuse this misconfiguration to leak sensitive information on the host to completely compromise the host and all data being processed by it.

References