Impact
Legacy RESTful routes under /go/admin/restful/* allowed pipeline group administrators to retrieve the full historical server configuration instead of a filtered view. The exposed data could contain agent auto‑registration keys, webhook invocation keys, encrypted material credentials, and administrator lists. A malicious pipeline group administrator could use the disclosed registration data to add a rogue agent that might obtain work or overwrite artifacts from other groups. The vulnerability does not modify configuration, and ordinary authenticated users cannot exploit it.
Affected Systems
GoCD versions from 12.3.1 through 26.1.0 are affected. The issue is fixed in version 26.1.0 and later releases.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA KEV. The attack requires an authenticated pipeline group administrator with access to the legacy admin REST API; the attacker then bypasses authorization controls to make full configuration visible.
OpenCVE Enrichment