GoCD Unauthenticated Takeover
ID: 8c1cc752-f9d6-5058-83d1-f0f3db5cd504
STIX ID: report--8c1cc752-f9d6-5058-83d1-f0f3db5cd504
Feed Name: Censys Blog
Threat Score
Date Published: 2021-10-30
Date Updated: 2026-04-27
Author: Mark Ellzey; Senior Security Researcher
...
...
A critical authentication regression in GoCD (introduced in 2018) allows unauthenticated access to addon endpoints (Business Continuity) that can disclose configuration, private encryption keys, and enable remote code execution; Censys found 458 hosts/592 internet-facing services potentially affected and administrators are urged to upgrade to GoCD 21.3.0 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
