Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

FeedsKontaktDatenschutz© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
GoCD_PoC_Supply_Chain_Attack — CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290 | Kitploit
Tools/GitHubGitHub/higorgabrieldcf/gocd_poc_supply_chain_attack
Payload-GenerierungSchwachstellenanalyseExploitationWebanwendungs-ExploitationPost-ExploitationSicherheitsvirtualisierungPenetrationstestsLieferkettensicherheit
Lernen & Bildung
Red Teaming
GitHubhigorgabrieldcf/gocd_poc_supply_chain_attack

GoCD_PoC_Supply_Chain_Attack

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

Repository anzeigen
219vor 20 TagenNoch nicht geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

GoCD 20.10.0 — PoC: CVE-2021-43287 · CVE-2021-43288 · CVE-2021-43289 · CVE-2021-43290

Autor / Author: Higor Farias — PRIDE Security

⚠️ AVISO LEGAL / LEGAL DISCLAIMER

[PT] Material produzido exclusivamente para fins educacionais e de pesquisa em segurança ofensiva. Utilize somente em ambientes controlados com autorização explícita. O uso indevido é de responsabilidade exclusiva do utilizador.

[EN] Produced exclusively for educational and authorized offensive security research purposes. Use only in controlled environments with explicit written permission. Misuse is the sole responsibility of the user.


Índice / Table of Contents

  1. Visão Geral / Overview
  2. Impacto na Cadeia de Suprimentos de Software / Software Supply Chain Impact
  3. Vulnerabilidades / Vulnerabilities
  4. Encadeamento de Ataque / Attack Chain
  5. Pré-requisitos / Prerequisites
  6. Ambiente PoC com Docker / PoC Docker Environment
  7. Uso dos Scripts / Script Usage
    • gocd_rce_noauth.py — RCE sem autenticação / Unauthenticated RCE
    • gocd_urldns.py — URLDNS / Detecção de desserialização
  8. Referências / References
  9. Cronologia / Timeline
  10. Mitigação / Mitigation

1. Visão Geral / Overview

[PT] O GoCD é uma plataforma de CI/CD mantida pela ThoughtWorks. Nas versões anteriores à 21.3.0, pesquisadores da SonarSource identificaram uma cadeia de vulnerabilidades explorável sem nenhuma autenticação. Os dois scripts deste repositório demonstram:

  • gocd_rce_noauth.py — exploração completa da cadeia até RCE (Execução Remota de Código), sem credenciais.
  • gocd_urldns.py — detecção out-of-band da desserialização Java via gadget chain URLDNS e callback DNS (requer credenciais válidas para listar agents registrados).

[EN] GoCD is a CI/CD platform maintained by ThoughtWorks. In versions prior to 21.3.0, SonarSource researchers identified a vulnerability chain exploitable with zero authentication. The two scripts in this repository demonstrate:

  • gocd_rce_noauth.py — full chain exploitation up to RCE (Remote Code Execution), without credentials.
  • gocd_urldns.py — out-of-band detection of Java deserialization via the URLDNS gadget chain and a DNS callback (requires valid credentials to list registered agents).

2. Impacto na Cadeia de Suprimentos de Software / Software Supply Chain Impact

[PT] O GoCD ocupa uma posição central na cadeia de entrega de software de uma organização: ele orquestra a compilação, os testes, a geração de artefatos e os deploys em produção. Ao comprometer o servidor GoCD via RCE (como demonstrado pelo gocd_rce_noauth.py), um atacante obtém controle sobre todos os estágios desse processo — podendo inserir backdoors em binários, falsificar artefatos ou exfiltrar código-fonte e credenciais antes mesmo que qualquer produto chegue ao usuário final. O cenário é análogo ao ataque à SolarWinds (2020), onde o acesso ao pipeline de build resultou na distribuição de malware para milhares de clientes.

[EN] GoCD occupies a central position in an organization's software delivery chain: it orchestrates builds, tests, artifact generation, and production deployments. By compromising the GoCD server via RCE (as demonstrated by gocd_rce_noauth.py), an attacker gains control over every stage of that process — enabling backdoor insertion into binaries, artifact tampering, or source code and credential exfiltration before any product reaches the end user. The scenario mirrors the SolarWinds attack (2020), where build pipeline access led to malware distribution to thousands of customers.```mermaid flowchart TD ATK(["🕵️ Atacante / Attacker\n(não autenticado / unauthenticated)"])

subgraph EXPLOIT ["Exploração / Exploitation"]
    E1["CVE-2021-43287\nLeitura do cruise_config\n(tokenGenerationKey + agentAutoRegisterKey)"]
    E2["Path Traversal\nLeitura de /etc/go/jetty.xml\ne /proc/self/environ"]
    E3["Registro de agente falso\nFake agent registration"]
    E4["Desserialização Java\n(AspectJWeaver gadget chains)\nSobrescreve jetty.xml + restart"]
    E5["💥 RCE no servidor GoCD\nRCE on GoCD server"]
    E1 --> E2 --> E3 --> E4 --> E5
end

subgraph PIPELINE ["Pipeline CI/CD comprometido / Compromised CI/CD Pipeline"]
    P1["📦 Build de artefatos\nBinary/artifact build"]
    P2["🧪 Execução de testes\nTest execution"]
    P3["📤 Publicação de pacotes\nPackage publication\n(npm, PyPI, Docker Hub...)"]
    P4["🚀 Deploy em produção\nProduction deployment"]
    P1 --> P2 --> P3 --> P4
end

subgraph IMPACT ["Impacto / Impact"]
    I1["🔑 Vazamento de credenciais\nCredential leak\n(tokens, SSH keys, API keys)"]
    I2["🦠 Backdoor em artefatos\nBackdoor in build artifacts"]
    I3["📂 Exfiltração de código-fonte\nSource code exfiltration"]
    I4["☠️ Ataque à cadeia de suprimentos\nSupply chain attack\n(usuários finais afetados / end users impacted)"]
    I1 & I2 & I3 --> I4
end

ATK --> EXPLOIT
E5 -->|"Controle total do runner\nFull runner control"| PIPELINE
P1 -->|"Artefatos envenenados\nPoisoned artifacts"| I2
P3 -->|"Pacotes maliciosos\nMalicious packages"| I4
P4 -->|"Produção comprometida\nCompromised production"| I4
E5 -->|"Leitura de secrets\nSecrets read"| I1
E5 -->|"Acesso ao repositório\nRepository access"| I3
---

## 3. Vulnerabilidades / Vulnerabilities

| CVE | Tipo / Type | CVSS 3.1 | CWE | Auth |
|-----|-------------|:---:|-----|:---:|
| **CVE-2021-43287** | Information Disclosure | **7.5 HIGH** | CWE-200 | ❌ Nenhuma / None |
| **CVE-2021-43288** | Stored XSS | **6.1 MEDIUM** | CWE-79 | Agent |
| **CVE-2021-43289** | Path Traversal — PUT | **8.1 HIGH** | CWE-22 | Agent |
| **CVE-2021-43290** | Path Traversal — GET | **8.1 HIGH** | CWE-22 | Agent |

### CVE-2021-43287 — Business Continuity: vazamento sem autenticação / unauthenticated leak

**[PT]** O endpoint `/go/add-on/business-continuity/api/cruise_config` devolve o XML completo de configuração do servidor **sem exigir autenticação**. O XML contém os atributos do elemento `<server>`, incluindo `agentAutoRegisterKey` e `tokenGenerationKey` — as duas chaves necessárias para registrar agentes e assinar requisições autenticadas. Adicionalmente, o parâmetro `pluginName` do endpoint de plugins aceita sequências de path traversal (`../../../../../../`), permitindo leitura de arquivos arbitrários do sistema — como `/proc/self/environ` e `/etc/go/jetty.xml`.

**[EN]** The `/go/add-on/business-continuity/api/cruise_config` endpoint returns the full server configuration XML **without requiring authentication**. The XML contains the `<server>` element attributes, including `agentAutoRegisterKey` and `tokenGenerationKey` — the two keys needed to register agents and sign authenticated requests. Additionally, the `pluginName` parameter of the plugin endpoint accepts path traversal sequences (`../../../../../../`), allowing arbitrary file reads — such as `/proc/self/environ` and `/etc/go/jetty.xml`.
Tool herunterladen