Thoughtworks

Gocd

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 03.01.2025 16:15:26
  • Zuletzt bearbeitet 01.08.2025 19:22:23

GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoreti...

  • EPSS 0.42%
  • Veröffentlicht 03.01.2025 16:15:26
  • Zuletzt bearbeitet 01.08.2025 19:24:56

GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server w...

  • EPSS 0.71%
  • Veröffentlicht 03.01.2025 16:15:26
  • Zuletzt bearbeitet 01.08.2025 20:03:29

GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or container as G...

  • EPSS 0.73%
  • Veröffentlicht 03.01.2025 16:15:26
  • Zuletzt bearbeitet 01.08.2025 20:09:15

GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing ...

  • EPSS 0.99%
  • Veröffentlicht 14.05.2024 15:14:46
  • Zuletzt bearbeitet 04.08.2025 14:43:31

GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting vulnerability on the loading page displayed while GoCD is starting, via abuse of a `redirect_to` quer...

  • EPSS 0.08%
  • Veröffentlicht 27.03.2023 21:15:12
  • Zuletzt bearbeitet 21.11.2024 07:55:42

GoCD is an open source continuous delivery server. In GoCD versions from 20.5.0 and below 23.1.0, if the server environment is not correctly configured by administrators to provide access to the relevant PostgreSQL or MySQL backup tools, the credenti...

  • EPSS 0.44%
  • Veröffentlicht 27.03.2023 21:15:12
  • Zuletzt bearbeitet 21.11.2024 07:55:41

GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configuration with a malicious pipeline label configuration can affect browser display of pipeline runs genera...

  • EPSS 9.47%
  • Veröffentlicht 14.10.2022 20:15:16
  • Zuletzt bearbeitet 21.11.2024 07:18:00

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or...

  • EPSS 0.31%
  • Veröffentlicht 14.10.2022 20:15:16
  • Zuletzt bearbeitet 21.11.2024 07:18:00

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 can allow one authenticated agent to impersonate another agent, and thus ...

  • EPSS 0.36%
  • Veröffentlicht 14.10.2022 20:15:15
  • Zuletzt bearbeitet 21.11.2024 07:18:00

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 leak the symmetric key used to encrypt/decrypt any secure variables/secre...