VendorsThoughtworksgocdall versions
Vulnerabilities

Thoughtworks GoCD

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2021-43290
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control.
Published 2022-04-14 · Modified
9.8EPSS 0.032
CVE-2021-44659
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the product's design allows an admin to configure outbound requests
Published 2021-12-22 · Modified
9.8EPSS 0.025
CVE-2024-56320
GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user
Published 2025-01-03 · Analyzed
9.4EPSS 0.007
CVE-2021-25924
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a malicious link which could change backup configurations or execute system commands in the post_backup_script field.
Published 2021-04-01 · Modified
9.3EPSS 0.008
CVE-2022-39311
Compromised agents may be able to execute remote code on GoCD Server
Published 2022-10-14 · Modified
9.1EPSS 0.017
CVE-2022-29184
Command Injection/Argument Injection in GoCD
Published 2022-05-20 · Modified
8.8EPSS 0.038
CVE-2021-43286
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.
Published 2022-04-14 · Modified
8.8EPSS 0.029
CVE-2022-24832
Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames
Published 2022-04-11 · Modified
8.2EPSS 0.017
CVE-2021-43287
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.
Published 2022-04-14 · Modified
7.5EPSS 0.280
CVE-2021-43289
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, but does not control the filename.
Published 2022-04-14 · Modified
7.5EPSS 0.023
CVE-2024-56322
GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionality
Published 2025-01-03 · Analyzed
7.2EPSS 0.007
CVE-2024-56324
GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins
Published 2025-01-03 · Analyzed
7.1EPSS 0.008
CVE-2022-39309
GoCD server secret encryption/decryption key leaked to agents during material serialization
Published 2022-10-14 · Modified
6.5EPSS 0.009
CVE-2022-39308
GoCD API authentication of user access tokens subject to timing attack during comparison
Published 2022-10-14 · Modified
6.5EPSS 0.007
CVE-2022-39310
Malicious agent may be able to impersonate another agent in GoCD
Published 2022-10-14 · Modified
6.5EPSS 0.007
CVE-2022-29183
Reflected XSS in GoCD
Published 2022-05-20 · Modified
6.1EPSS 0.009
CVE-2024-28866
GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-up
Published 2024-05-13 · Analyzed
6.1EPSS 0.004
CVE-2022-36088
GoCD Windows installations outside default location inadequately restrict installation file permissions
Published 2022-09-07 · Modified
5.5EPSS 0.002
CVE-2021-43288
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report.
Published 2022-04-14 · Modified
5.4EPSS 0.009
CVE-2022-29182
DOM-based XSS in GoCD
Published 2022-05-20 · Modified
5.4EPSS 0.008
CVE-2023-28629
Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocd
Published 2023-03-27 · Modified
5.4EPSS 0.005
CVE-2023-28630
Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocd
Published 2023-03-27 · Modified
4.4EPSS 0.003
CVE-2024-56321
GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host access
Published 2025-01-03 · Analyzed
3.8EPSS 0.005