Imperfect CSRF To Overwrite Server Config at /go/admin/restful/configuration/file/POST/xml
Medium
G
GoCD
Submitted None
Team Summary
Official summary from GoCD
The /go/admin/restful/configuration/file/POST/xml path is vulnerable to Cross-Site Request Forgery that can result in an unauthorized user adding to the server cruise-config.xml and gaining complete control of the server. Successful exploitation is made difficult by the need for the admin to be served malicious HTML and for the attacker to have a copy of historical config, such as the nearly-empty empty placeholder file that gets initially generated upon install.
Actions:
Reported by
4cad
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-Site Request Forgery (CSRF)