CVE-2024-56320 affects GoCD versions prior to 24.5.0, allowing authenticated users to escalate privileges to administrator level due to improper authorization in the "Configuration XML" UI and API. This vulnerability carries a CVSS score of 8.8 (High), indicating a low-complexity attack that can lead to complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, immediate upgrade to GoCD 24.5.0 is recommended. If upgrading is not feasible, blocking access paths with a /go/rails/ prefix via a reverse proxy or WAF can mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 24.5.0CPE matchmatch criteria | cpe:2.3:a:thoughtworks:gocd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.