{"id":"CVE-2022-39311","summary":"Compromised agents may be able to execute remote code on GoCD Server","details":"GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or compromised agent. The Spring RemoteInvocation endpoint exposed agent communication and allowed deserialization of arbitrary java objects, as well as subsequent remote code execution. Exploitation requires agent-level authentication, thus an attacker would need to either compromise an existing agent, its network communication or register a new agent to practically exploit this vulnerability. This issue is fixed in GoCD version 21.1.0. There are currently no known workarounds.","aliases":["GHSA-2hjh-3p3p-8hcm"],"modified":"2026-08-12T13:33:12.962011Z","published":"2022-10-14T00:00:00Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39311.json"},"references":[{"type":"WEB","url":"https://www.gocd.org/releases/#21-1-0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39311.json"},{"type":"ADVISORY","url":"https://github.com/gocd/gocd/security/advisories/GHSA-2hjh-3p3p-8hcm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39311"},{"type":"FIX","url":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gocd/gocd","events":[{"introduced":"0"},{"fixed":"5a4959c7c4ede49165ec961b0219126cd5aa9e52"},{"fixed":"7b88b70d6f7f429562d5cab49a80ea856e34cdc8"}],"database_specific":{"cpe":"cpe:2.3:a:thoughtworks:gocd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"21.1.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["20.10.0","20.9.0","20.8.0","20.7.0","20.6.0","20.5.0","20.4.0","20.3.0","20.2.0","20.1.0","19.12.0","19.11.0","19.10.0","19.9.0","19.8.0","19.7.0","19.6.0","19.5.0","19.4.0","19.3.0","19.2.0","19.1.0","18.12.0","18.11.0","18.10.0","18.9.0","18.8.0","18.7.0","18.6.0","18.5.0","18.4.0","18.3.0","18.2.0","18.1.0","17.12.0","17.11.0","17.10.0","17.9.0","17.8.0","17.7.0","17.6.0","17.5.0","17.4.0","17.3.0","17.2.0","17.1.0","16.12.0","16.11.0","16.10.0","16.9.0","16.8.0","16.7.0","16.6.0","16.5.0","16.4.0","16.3.0","16.2.0","16.1.0","15.3.0","15.2.0","15.1.0","14.4.0","14.3.0","14.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39311.json","vanir_signatures_modified":"2026-08-12T13:33:12Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/main/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporter.java"},"deprecated":false,"digest":{"line_hashes":["19141264882242089066190477312212400886","65368804272985222506993493963227304702","279240094694590922399506977405419403091","4634291003029796828372107198679636487","171936443547283794604111134522291090585","161592639817624653600010690301019545422","294839270021821898998836670793539711655","86475630074448236166403931078685603094","256642386779537776043339327029630495616","204644290268058482113790874509945184256","268533318486492899644965647339809402793","337122935548239079432244872264610771798","31880904644335322732259723283826130707","304146289372686541914522020897451525187","253386746721606668633918635283844009568","248902180802581797805373182676982770474","200398346448091562894317655718868614490","108486651742063932891150621062552294424"],"threshold":0.9},"id":"CVE-2022-39311-00e48e96"},{"signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"reportCompleted_allowedForSameUUID"},"deprecated":false,"digest":{"function_hash":"264876036211125198649703837235021202426","length":413},"id":"CVE-2022-39311-11fcc6d0","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"24775687799636521463861337672161254573","length":372},"id":"CVE-2022-39311-156b0a77","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"getWork_rejectedForDifferentUUID"}},{"deprecated":false,"digest":{"function_hash":"255248565567386886043624198835301107598","length":485},"id":"CVE-2022-39311-23953ef1","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"reportCompleting_rejectedForDifferentUUID"}},{"deprecated":false,"digest":{"function_hash":"162261550580316591402524574695029761502","length":324},"id":"CVE-2022-39311-34f4cd00","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"rejectsUnknownMethod"}},{"signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"reportCurrentStatus_allowedForSameUUID"},"deprecated":false,"digest":{"function_hash":"295940351295725300814319591944122451204","length":417},"id":"CVE-2022-39311-386ec695","signature_type":"Function"},{"digest":{"function_hash":"152163371270306280661509886729805216721","length":173},"id":"CVE-2022-39311-4b033045","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"setup"},"deprecated":false},{"digest":{"function_hash":"22239923531564292969217893632257018095","length":369},"id":"CVE-2022-39311-561f1393","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"ping_rejectedForDifferentUUID"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"307619262242404505005898324610224076195","length":488},"id":"CVE-2022-39311-841e541a","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"reportCurrentStatus_rejectedForDifferentUUID"}},{"id":"CVE-2022-39311-8b65a6d6","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"getCookie_rejectedForDifferentUUID"},"deprecated":false,"digest":{"function_hash":"8942086051963856815786312425219670933","length":374}},{"signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/main/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporter.java","function":"handleRequest"},"deprecated":false,"digest":{"function_hash":"144901314905224106589196783987020754313","length":374},"id":"CVE-2022-39311-99c7badd","signature_type":"Function"},{"target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"getWork_allowedForSameUUID"},"deprecated":false,"digest":{"function_hash":"172759495741370860292444603209777338374","length":345},"id":"CVE-2022-39311-9bb3dd00","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8"},{"deprecated":false,"digest":{"function_hash":"179895329539702031729133407190502489531","length":484},"id":"CVE-2022-39311-a65c352d","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"reportCompleted_rejectedForDifferentUUID"}},{"target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"reportCompleting_allowedForSameUUID"},"deprecated":false,"digest":{"length":414,"function_hash":"229502289649802732659143687680513623832"},"id":"CVE-2022-39311-b0f8621d","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8"},{"source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"deserializingWith"},"deprecated":false,"digest":{"function_hash":"191575885074225474716276221652479707041","length":1031},"id":"CVE-2022-39311-b2f8dcdc","signature_type":"Function","signature_version":"v1"},{"id":"CVE-2022-39311-b5772663","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"ping_allowedForSameUUID"},"deprecated":false,"digest":{"function_hash":"274614403774843973133570228812252250007","length":342}},{"deprecated":false,"digest":{"line_hashes":["229949243028401414399199440247468289543","194263074349564599967271675914153950269","165790515257549403387632937682293457270","132275644172951144038741701269142019935","124244960272472393043123323185368925742","150307537546000783523397362058899547335","150964683793488520441872756619518198421","102353433584901986204630502119750731963","134855171333936206636742420111991707497","117766224598631373870762319356590866298","297821289897868015763536854919434138621","272603406767089790865948533795631092574","128899735985555672197287561463859727392","12191808546091365941716510626080189215","256692626474563938092858583527890301289","128514908406118984112844715372650859596","142728550536074686353022751517419404583","328599596943770311455111262608092266326","184884243036526216817478785474144106578","284609029872269395529225199756608251997","225983291579968411753757237739975996990","194987997042364376167962504038786464573","98615765895013056909648435366269510281","216566371682870430928592924063853882850","95980465352536953015144560900164388409","156966935719390101141595310901694913088","30704144220320627912497005906053052747","202001529272116654354224354478426408641","189122897207893512851337187632911855662","152427529794525709344197632157823262776","315421050253273590927950598006548869460","125179145513924610582379817715759211145","248934113918570520082664265213743132771","171858654958546161963811617211052442735","110597169319038248102906993859532079574","62211570483075243370622037955149270938","11524654850336959020730411198667125518","45871290380479836549744606863800091023","148763460657382481278708246323386291604","117287835919031742436927453380507134094","197776068161944648516904363637966381243","141909050522062621419303210524918062437","64939259962865056627797636233622353233","302517349704684565371010606434638007227","197440656073140220539893733020189924471","39920399193058562506693620651128805772","227753252551050689420581682742484356791","21294666140951197366008368834376556883","102816842801947456953538264057196137918","42961761882789366468443947404380060753","104061277441236629610613325121417900799","254267094200038070591586931620637556401","254862810195967579533183303286792976788","256003481599020908060875076053903452236","183650407133403794644758735168602372571","66484648401960656288361755926742949446","331064502670243096641163557341648490063","168303723294207202371342318682783697668","290699482403673474721785128989139549381","188313731099063875050435767452110235492","170182363339929806496717531156515542443","40965997131371771632064302921311592820","229211271251750828530497026261099255733","249265701271003158139078902342451468709","315746096961645088081364775957799756496","322753615886840198217547337321275268783","51053327911236387293455963864378385560","2614713510710966710634201477936989379","42457420170998271116130632965534025970","43855484392961447679459705346083233579","203672615121812291370332834518288711082","36572196855252785498699507006885165614","222479569557677228873272919183077636197","26998043927137714909935541749398191918","132891889760921241302858174285723604334","96940490325278741804891481932864902857","38422398430171535712291190301969426805","113296997456023722537147964967085505580","209930229713509137586183595728143908448","256834039695672330342080516359903046860","181865345226592667963719729387865563874","207706901633009827350658287167979126802","120134845564439734973040997605650243714","123735423917288910083045729919915929887","333047637732455800535100303364198910639","299232152522590263994715264647528994867","245844439289952819395681154181813037291"],"threshold":0.9},"id":"CVE-2022-39311-b777e243","signature_type":"Line","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java"}},{"id":"CVE-2022-39311-be1e26fd","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"function":"isIgnored_rejectedForDifferentUUID","file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java"},"deprecated":false,"digest":{"function_hash":"58794484439270042084988886550694409094","length":426}},{"source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"isIgnored_allowedForSameUUID"},"deprecated":false,"digest":{"function_hash":"234380149529745780420703886612836168940","length":377},"id":"CVE-2022-39311-c3d0808d","signature_type":"Function","signature_version":"v1"},{"target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"getCookie_allowedForSameUUID"},"deprecated":false,"digest":{"length":347,"function_hash":"21886746245966837476111351605227135977"},"id":"CVE-2022-39311-d00f5efe","signature_type":"Function","signature_version":"v1","source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8"},{"source":"https://github.com/gocd/gocd/commit/7b88b70d6f7f429562d5cab49a80ea856e34cdc8","target":{"file":"server/src/test-fast/java/com/thoughtworks/go/remote/AgentRemoteInvokerServiceExporterTest.java","function":"getProxyForService"},"deprecated":false,"digest":{"function_hash":"290111226167782141565145927688775614205","length":37},"id":"CVE-2022-39311-dd835109","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}