GoCD Windows installations outside default location inadequately restrict installation file permissions
Published Sep 7, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.23%
Description
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malicious user with local access to the server GoCD Server or Agent are installed on to modify executables or components of the installation. This does not affect zip file-based installs, installations to other platforms, or installations inside `Program Files` or `Program Files (x86)`. This issue is fixed in GoCD 22.2.0 installers. As a workaround, if the server or agent is installed outside of `Program Files (x86)`, verify the the permission of the Server or Agent installation directory to ensure the `Everyone` user group does not have `Full Control`, `Modify` or `Write` permissions.
Affected products
-
- Version < 22.2.0StatusaffectedConstraints-
- Version
- < 22.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
1 other source (GitHub) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 23, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.23% (0.00231) | 12.58th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.21% (0.00212) | 11.38th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.02% (0.00016) | 1.99th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Sep 8, 2022 | 0.95% (0.00950) | 30.59th | v2 (v2022.01.01) |
References (4)
- https://github.com/gocd/gocd/commit/96add9605096ab50c5cd4c229be1d503aff506a6 x_refsource_MISCPatchThird Party Advisory
- https://github.com/gocd/gocd/releases/tag/22.2.0 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/gocd/gocd/security/advisories/GHSA-gpv4-xqhc-5vcj x_refsource_CONFIRMMitigationThird Party Advisory
- https://www.gocd.org/releases/#22-2-0 x_refsource_MISCRelease NotesThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/gocd/gocd/commit/96add9605096ab50c5cd4c229be1d503aff506a6 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/gocd/gocd/releases/tag/22.2.0 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/gocd/gocd/security/advisories/GHSA-gpv4-xqhc-5vcj | x_refsource_CONFIRMMitigationThird Party Advisory | |
| https://www.gocd.org/releases/#22-2-0 | x_refsource_MISCRelease NotesThird Party Advisory |
Change history (0)
No recorded changes yet.