Critical flaw in GoCD provides platform for supply chain attacks

Discussion in 'other security issues & news' started by guest, Oct 28, 2021.

  1. guest

    guest Guest

    Critical flaw in GoCD provides platform for supply chain attacks
    Vulnerability in software used by Fortune 500 firms raises fears of SolarWinds-like impact
    October 28, 2021

    https://portswigger.net/daily-swig/critical-flaw-in-gocd-provides-platform-for-supply-chain-attacks
    SonarSource: Agent 007: Pre-Auth Takeover of Build Pipelines in GoCD
     
  2. guest

    guest Guest

    GoCD bug chain provides second springboard to supply chain attacks
    Follow-up to recent GoCD disclosure provides additional path to infiltrating build environments
    November 11, 2021
    https://portswigger.net/daily-swig/...es-second-springboard-to-supply-chain-attacks
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.