PT-2026-96135 · Gocd · Gocd
CVE-2026-55870
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GoCD versions prior to 26.1.0
Description
GoCD can return unmasked credentials stored in the userinfo portion of source control material URLs. This occurs through several read-only APIs available to regular authenticated users. While dedicated password fields remain encrypted, legacy configurations that permit credentials within material URLs may not be consistently masked across all mixed-use APIs for every material type. Consequently, an authenticated user with access to an affected pipeline can obtain these embedded credentials.
Recommendations
Update to version 26.1.0.
Avoid storing credentials in the userinfo portion of source control material URLs and use dedicated username and password fields or secret-management plugins instead.
Exploit
Fix
Information Disclosure
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gocd