GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by packa…
提示
摘要
GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage Detail, Job/Build Detail, Value Stream Map, and Pipeline History views. A user with write access to a material tracked by GoCD can store arbitrary HTML or JavaScript in a forged package material comment, which executes in the browser session of a user who later …
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/gocd/gocd/commit/a03eeeaa4a85edfc9053e743610547d4fcf7aea6
- https://github.com/gocd/gocd/releases/tag/26.1.0
- https://github.com/gocd/gocd/security/advisories/GHSA-pp5x-wgv2-g37p
- https://www.gocd.org/releases/#26-1-0
时间线
- nvd_ingest NVD