Thoughtworks / Gocd
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-56324 | GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins | LOW | 2.1 | Jan 3, 2025 |
| CVE-2024-56322 | GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionality | LOW | 2.1 | Jan 3, 2025 |
| CVE-2024-56321 | GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host access | LOW | 3.8 | Jan 3, 2025 |
| CVE-2024-56320 | GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user | CRITICAL | 9.4 | Jan 3, 2025 |
| CVE-2024-28866 | GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-up | MEDIUM | 6.1 | May 13, 2024 |
| CVE-2023-28629 | Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocd | MEDIUM | 5.4 | Mar 27, 2023 |
| CVE-2023-28630 | Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocd | MEDIUM | 4.4 | Mar 27, 2023 |
| CVE-2022-39311 | Compromised agents may be able to execute remote code on GoCD Server | CRITICAL | 9.1 | Oct 14, 2022 |
| CVE-2022-39310 | Malicious agent may be able to impersonate another agent in GoCD | MEDIUM | 6.5 | Oct 14, 2022 |
| CVE-2022-39309 | GoCD server secret encryption/decryption key leaked to agents during material serialization | MEDIUM | 6.5 | Oct 14, 2022 |
| CVE-2022-39308 | GoCD API authentication of user access tokens subject to timing attack during comparison | MEDIUM | 6.5 | Oct 14, 2022 |
| CVE-2022-36088 | GoCD Windows installations outside default location inadequately restrict installation file permissions | MEDIUM | 5.5 | Sep 7, 2022 |
| CVE-2022-29184 | Command Injection/Argument Injection in GoCD | HIGH | 8.8 | May 20, 2022 |
| CVE-2022-29183 | Reflected XSS in GoCD | MEDIUM | 6.1 | May 20, 2022 |
| CVE-2022-29182 | DOM-based XSS in GoCD | MEDIUM | 5.4 | May 20, 2022 |
| CVE-2021-43286 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line inje… | HIGH | 8.8 | Apr 14, 2022 |
| CVE-2021-43288 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report. | MEDIUM | 5.4 | Apr 14, 2022 |
| CVE-2021-43289 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary director… | HIGH | 7.5 | Apr 14, 2022 |
| CVE-2021-43290 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD… | CRITICAL | 9.8 | Apr 14, 2022 |
| CVE-2021-43287 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD se… | HIGH | 7.5 | Apr 14, 2022 |
| CVE-2022-24832 | Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames | HIGH | 8.2 | Apr 11, 2022 |
| CVE-2021-44659 | Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Requ… | CRITICAL | 9.8 | Dec 22, 2021 |
| CVE-2021-25924 | In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An atta… | HIGH | 8.8 | Apr 1, 2021 |
Showing 1 to 23 of 23 CVEs