Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g7mm-9vx7-jm7h

Опубликовано: 14 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.1

Описание

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

Impact

A vulnerability in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged agent_id value into outgoing gRPC metadata. The server correctly verified the JWT token but then discarded the verified agent identity in favor of the client-supplied value.

Patches

Direct patch: https://github.com/woodpecker-ci/woodpecker/pull/6567 Later proper fix: https://github.com/woodpecker-ci/woodpecker/pull/6569

Workarounds

Disable org agents (WOODPECKER_DISABLE_USER_AGENT_REGISTRATION=true) and delete existing ones

Resources

Public ref: https://github.com/woodpecker-ci/woodpecker/issues/6541 Private com: https://github.com/woodpecker-ci/woodpecker-security/issues/21

Пакеты

Наименование

go.woodpecker-ci.org/woodpecker/v3

go
Затронутые версииВерсия исправления

>= 3.0.0, < 3.14.1

3.14.1

EPSS

Процентиль: 35%
0.00427
Низкий

7.1 High

CVSS4

Дефекты

CWE-290
CWE-639

Связанные уязвимости

nvd
около 2 месяцев назад

Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged `agent_id` value into outgoing gRPC metadata. The server correctly verified the JWT token but then discarded the verified agent identity in favor of the client-supplied value. Version 3.14.1 patches the issue. As a workaround, disable org agents (`WOODPECKER_DISABLE_USER_AGENT_REGISTRATION=true`) and delete existing ones.

debian
около 2 месяцев назад

Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to v ...

EPSS

Процентиль: 35%
0.00427
Низкий

7.1 High

CVSS4

Дефекты

CWE-290
CWE-639