CVE-2023-28630 is a credential leakage vulnerability affecting GoCD versions 20.5.0 through 22.x.x, where database access credentials (PostgreSQL or MySQL) can be exposed in admin alerts if the server is misconfigured to enable backups without the necessary pg_dump or mysqldump utilities. This issue has a CVSS score of 4.4 (Medium), indicating a local attack vector with low complexity, requiring high privileges, and resulting in high confidentiality impact. While the vulnerability is not known to be actively exploited, there is no public exploit code available, and it has received minimal community discussion or media coverage. Users are advised to upgrade to GoCD 23.1.0 or ensure proper backup tool availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20.5.0, < 23.1.0CPE matchmatch criteria | cpe:2.3:a:thoughtworks:gocd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.