Impact
The vulnerability allows an authenticated, non‑administrator user to access the internal pipeline structure API endpoint that should be restricted to administrators. This endpoint returns the list of users and role names configured in the system without revealing role assignments. Because the endpoint does not permit data modification, the flaw is primarily an information disclosure that can be leveraged to enumerate valid user accounts and available roles, potentially aiding targeted social‑engineering or credential‑guessing attacks.
Affected Systems
The issue affects instances of GoCD with versions from 20.2.0 up to and including 26.0.x. Upgrading to version 26.1.0 or later resolves the problem.
Risk and Exploitability
The CVSS score of 4.3 reflects a medium impact and the absence of a EPSS score indicates uncertain exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The attack vector is limited to logged‑in users because only authenticated users can reach the endpoint, but it does not require elevated privileges. A lower‑privileged user can enumerate user and role names, which may support further attacks.
OpenCVE Enrichment