GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authenticated GoCD user with an existing GoCD user account could abuse this vulnerability to access information intended only for GoCD admins, or to escalate their privileges to that of a GoCD admin in a persistent manner. it is not possible for this vulnerability to be abused prior to authentication/login. The issue is fixed in GoCD 24.5.0. GoCD users who are not able to immediate upgrade can mitigate this issue by using a reverse proxy, WAF or similar to externally block access paths with a `/go/rails/` prefix. Blocking this route causes no loss of functionality. If it is not possible to upgrade or block the above route, consider reducing the GoCD user base to more trusted set of users, including temporarily disabling use of plugins such as the guest-login-plugin, which allow limited anonymous access as a regular user account.
総合評価: CVE-2024-56320 は中リスク(53.8/100)。CVSS 深刻度は重大。悪用される可能性が高い(EPSS 0.71%、49 パーセンタイル) 推奨対応: 影響資産を整理し、修補計画に組み込んでください。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.59% | 0.71% | -0.88% |
| 2 | 2026-05-25 | 1.18% | 1.59% | +0.41% |
| 3 | 2026-04-08 | — | 1.18% | — |
EPSS の全履歴 (全 33 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 9.4 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| thoughtworks | gocd | < 24.5.0 | cpe:2.3:a:thoughtworks:gocd:*:*:*:*:*:*:*:* |
| URL | タグ |
|---|---|
| https://github.com/gocd/gocd/commit/68b598b97bd283a5a85e20d018d69fe86acf4165 | Patch |
| https://github.com/gocd/gocd/releases/tag/24.5.0 | Release Notes |
| https://github.com/gocd/gocd/security/advisories/GHSA-346h-q594-rj8j | Vendor Advisory |
| https://www.gocd.org/releases/#24-5-0 | Release Notes |