Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-39309

22
FAUCET Score

CVE-2022-39309 affects GoCD versions prior to 21.1.0, where a symmetric key used for encrypting secure variables is leaked to authenticated agents. This medium-severity vulnerability (CVSS 6.5) allows a compromised agent to extract the key from memory, potentially enabling an attacker to decrypt sensitive configuration values intended for other agents or environments. There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. The issue is resolved in GoCD version 21.1.0, and no workarounds exist for earlier versions.

Impacted Technologies

VendorProductVersion(s)CPE
< 21.1.0CPE matchmatch criteria
cpe:2.3:a:thoughtworks:gocd:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.9MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.80%
Probability of exploitation in next 30 days
EPSS Percentile
53.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0080 is in the 63rd percentile among its peer group of 21,951 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / gocd/gocd/commit/691b479f1310034992da141760e9c5d1f5b60e8a
PatchThird Party Advisory
github.com / gocd/gocd/releases/tag/21.1.0
Release NotesThird Party Advisory
github.com / gocd/gocd/security/advisories/GHSA-f9qg-xcxq-cgv9
PatchRelease NotesThird Party Advisory
gocd.org / releases
Release NotesVendor Advisory