CVE-2022-24832 is a medium-severity vulnerability affecting the GoCD continuous delivery server, specifically its bundled gocd-ldap-authentication-plugin. The flaw allows an authenticated GoCD user to craft malicious LDAP queries due to improper escaping of special characters in usernames. This can lead to the deduction of sensitive information about other users or entries within the LDAP database, such as alternate fields or hashed passwords, through brute-force methods. The vulnerability has a CVSS score of 6.8 (Medium) and requires an existing LDAP-authenticated GoCD user with malicious intent, making it a high-impact but high-complexity attack. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.5.0, < 22.1.0CPE matchmatch criteria | cpe:2.3:a:thoughtworks:gocd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.