
Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.
A full vulnerability assessment & penetration test against OWASP CICD-Goat — a deliberately vulnerable CI/CD environment (Jenkins, Gitea, GitLab, CTFd) — mapped end-to-end against the OWASP Top 10 CI/CD Security Risks.
| Repository | What's in it |
|---|---|
| CICD-Goat-Vapt-Writeup (this repo) | Full VAPT writeup against OWASP CICD-Goat — 16 findings including CVE-2024-23897, mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs and interview-ready summaries |
| From-Dev-To-Attacker | My flagship field journal — 67 original write-ups on vulnerability patterns, written from a developer's lens, with enterprise domain-impact framing across Income Tax, Banking, Retail, E-commerce, Freight Logistics, and Education |
| From-Pentester-To-Red-Teamer | My structured 24-month roadmap for transitioning from Web/API pentesting into Red Teaming — phases, labs, certifications, and progress tracked openly as I work through it |
| AppSec-From-The-Trenches | Pentest tools & methodology reference — how I actually use Burp Suite, Nmap, Metasploit, Hydra, Hashcat, and more, plus my WAPT methodology |
| API-From-The-Trenches | Deep-dive API security series — OWASP API Top 10 coverage, BOLA, JWT attacks, GraphQL testing, full methodology |
| Bug-Bounty-Hunting-Companion | Real, publicly-disclosed bug bounty reports broken into reproducible checklists |
| DarkWeb-From-The-Trenches | Threat intelligence & dark web OSINT methodology — credential leak monitoring, ransomware tracking, pre-engagement TI |
| .pcap-Arsenal | Packet captures organized by protocol, for Web/API/Network-layer analysis and learning |
| Pentest-Engagement-Playbook | Consultant-grade scoping, ROE, severity rationale, and executive reporting templates — the client-facing operational playbook behind an engagement |
Most CI/CD security writeups either stay purely theoretical (a slide explaining "poisoned pipeline execution") or purely CTF-flag-chasing (a one-line "here's the flag, next"). This repo tries to do neither: every finding below is a fully validated, PoC-backed vulnerability, mapped to a specific OWASP CI/CD-SEC risk category, written the way you'd actually want to explain it in an interview or a real client report — including the dead ends, the wrong assumptions, and how they got corrected.
If you're studying for an AppSec/DevSecOps/CI-CD-security interview, prepping for a pentest engagement involving a CI/CD toolchain, or just want a concrete, hands-on tour of what "Poisoned Pipeline Execution" or "Insufficient Credential Hygiene" actually looks like on the wire — this is written for you.
| Field | Value |
|---|---|
| Target | OWASP CICD-Goat — local Docker Compose deployment |
| Engagement type | Authorized self-directed learning lab (grey-box) |
| Tech stack | Jenkins 2.332.1, Gitea 1.16.5, GitLab 15.11.13-ee, CTFd, Docker Compose |
| Scope | localhost:3000 (Gitea), :8080/:50000 (Jenkins), :4000 (GitLab), :8000 (CTFd), :8008 (prod-sim) |
| Methodology | Phase 0–3 (Scope → Fingerprinting → Vulnerability ID → Exploitation) |
Full rules of engagement: docs/00-engagement-overview.md.
⚠️ All testing in this repo was performed against the tester's own local, disposable, intentionally-vulnerable Docker Compose lab. No production systems, shared infrastructure, or third-party data were involved. Spin up your own copy of CICD-Goat from the official repo before trying any of this yourself.
| ID | Title | Severity | OWASP CI/CD Mapping | CTFd Flag |
|---|---|---|---|---|
| F-010 | Secrets exposure in Jenkins build console logs → credential theft → unauthorized repo write | CRITICAL | CICD-SEC-6, -4, -2 | flag1, flag2 |
| F-013 | Insecure auto-merge logic bypasses code review (PR-wide word-diff heuristic) | CRITICAL | CICD-SEC-1, -5 | flag10 |
| F-016 | CVE-2024-23897 — Jenkins CLI arbitrary file read on the controller | CRITICAL | CICD-SEC-7 | flag8 |
| F-017 | GitLab shared-runner registration token → instance-wide CI/CD secret theft | CRITICAL | CICD-SEC-2, -6 | flag11 |
| F-019 | Jenkins controller-node code execution via agent label override | CRITICAL | CICD-SEC-5, -4 | flag5 |
| F-018 | Decoupled pipeline repo + branch exclusion filter bypass | HIGH | CICD-SEC-4, -6 | flag3 |
| F-020 | Shared agent filesystem exposes FreeStyle job credential | HIGH | CICD-SEC-6, -5 | flag6 |
| F-021 | Checkov SAST config override enables undetected IaC misconfiguration | HIGH | CICD-SEC-1, -8 | flag7 |
| F-014 | Flask session secret key derived from a CI/CD pipeline variable | HIGH | CICD-SEC-6 | flag11 (via F-017) |
Plus 6 informational / supporting findings (positive controls, RBAC boundary confirmations, minor info-disclosure) in findings/informational/.