Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CICD-Goat-Vapt-Writeup — Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries. | Kitploit
Tools/GitHubGitHub/dheeraj-jayaswal/cicd-goat-vapt-writeup
ReconnaissanceVulnerability AnalysisExploitationCTFPenetration TestingDevSecOpsMisconfigurationLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
dheeraj-jayaswal/cicd-goat-vapt-writeup

CICD-Goat-Vapt-Writeup

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.

View Repository
12312 days agoNot yet reviewed

CICD-Goat VAPT Writeup

A full vulnerability assessment & penetration test against OWASP CICD-Goat — a deliberately vulnerable CI/CD environment (Jenkins, Gitea, GitLab, CTFd) — mapped end-to-end against the OWASP Top 10 CI/CD Security Risks.

Made for OWASP CICD-Goat Findings Flags Captured License

LinkedIn Location


🧭 How This Fits With My Other Repos

RepositoryWhat's in it
CICD-Goat-Vapt-Writeup (this repo)Full VAPT writeup against OWASP CICD-Goat — 16 findings including CVE-2024-23897, mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs and interview-ready summaries
From-Dev-To-AttackerMy flagship field journal — 67 original write-ups on vulnerability patterns, written from a developer's lens, with enterprise domain-impact framing across Income Tax, Banking, Retail, E-commerce, Freight Logistics, and Education
From-Pentester-To-Red-TeamerMy structured 24-month roadmap for transitioning from Web/API pentesting into Red Teaming — phases, labs, certifications, and progress tracked openly as I work through it
AppSec-From-The-TrenchesPentest tools & methodology reference — how I actually use Burp Suite, Nmap, Metasploit, Hydra, Hashcat, and more, plus my WAPT methodology
API-From-The-TrenchesDeep-dive API security series — OWASP API Top 10 coverage, BOLA, JWT attacks, GraphQL testing, full methodology
Bug-Bounty-Hunting-CompanionReal, publicly-disclosed bug bounty reports broken into reproducible checklists
DarkWeb-From-The-TrenchesThreat intelligence & dark web OSINT methodology — credential leak monitoring, ransomware tracking, pre-engagement TI
.pcap-ArsenalPacket captures organized by protocol, for Web/API/Network-layer analysis and learning
Pentest-Engagement-PlaybookConsultant-grade scoping, ROE, severity rationale, and executive reporting templates — the client-facing operational playbook behind an engagement

Why this exists

Most CI/CD security writeups either stay purely theoretical (a slide explaining "poisoned pipeline execution") or purely CTF-flag-chasing (a one-line "here's the flag, next"). This repo tries to do neither: every finding below is a fully validated, PoC-backed vulnerability, mapped to a specific OWASP CI/CD-SEC risk category, written the way you'd actually want to explain it in an interview or a real client report — including the dead ends, the wrong assumptions, and how they got corrected.

If you're studying for an AppSec/DevSecOps/CI-CD-security interview, prepping for a pentest engagement involving a CI/CD toolchain, or just want a concrete, hands-on tour of what "Poisoned Pipeline Execution" or "Insufficient Credential Hygiene" actually looks like on the wire — this is written for you.

Target environment

FieldValue
TargetOWASP CICD-Goat — local Docker Compose deployment
Engagement typeAuthorized self-directed learning lab (grey-box)
Tech stackJenkins 2.332.1, Gitea 1.16.5, GitLab 15.11.13-ee, CTFd, Docker Compose
Scopelocalhost:3000 (Gitea), :8080/:50000 (Jenkins), :4000 (GitLab), :8000 (CTFd), :8008 (prod-sim)
MethodologyPhase 0–3 (Scope → Fingerprinting → Vulnerability ID → Exploitation)

Full rules of engagement: docs/00-engagement-overview.md.

⚠️ All testing in this repo was performed against the tester's own local, disposable, intentionally-vulnerable Docker Compose lab. No production systems, shared infrastructure, or third-party data were involved. Spin up your own copy of CICD-Goat from the official repo before trying any of this yourself.

Results at a glance

IDTitleSeverityOWASP CI/CD MappingCTFd Flag
F-010Secrets exposure in Jenkins build console logs → credential theft → unauthorized repo writeCRITICALCICD-SEC-6, -4, -2flag1, flag2
F-013Insecure auto-merge logic bypasses code review (PR-wide word-diff heuristic)CRITICALCICD-SEC-1, -5flag10
F-016CVE-2024-23897 — Jenkins CLI arbitrary file read on the controllerCRITICALCICD-SEC-7flag8
F-017GitLab shared-runner registration token → instance-wide CI/CD secret theftCRITICALCICD-SEC-2, -6flag11
F-019Jenkins controller-node code execution via agent label overrideCRITICALCICD-SEC-5, -4flag5
F-018Decoupled pipeline repo + branch exclusion filter bypassHIGHCICD-SEC-4, -6flag3
F-020Shared agent filesystem exposes FreeStyle job credentialHIGHCICD-SEC-6, -5flag6
F-021Checkov SAST config override enables undetected IaC misconfigurationHIGHCICD-SEC-1, -8flag7
F-014Flask session secret key derived from a CI/CD pipeline variableHIGHCICD-SEC-6flag11 (via F-017)

Plus 6 informational / supporting findings (positive controls, RBAC boundary confirmations, minor info-disclosure) in findings/informational/.

How the findings chain together

Download Tool