Skip to content
Noroxi

thoughtworks records

24 published records for vendor thoughtworks.

All records

24 records
  • An issue was discovered in ThoughtWorks GoCD before 21.3.0.

    CriticalCVSS 9.8No exploitEPSS 3%

    thoughtworks · gocdApr 14, 2022

  • Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve

    CriticalCVSS 9.8No exploitEPSS 3%

    thoughtworks · gocdDec 22, 2021

  • An issue was discovered in ThoughtWorks GoCD before 21.3.0.

    HighCVSS 7.5Proof of conceptEPSS 27%

    thoughtworks · gocdApr 14, 2022

  • GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user

    CriticalCVSS 9.4No exploitEPSS 1%

    thoughtworks · gocdJan 3, 2025

  • Command Injection/Argument Injection in GoCD

    HighCVSS 8.8No exploitEPSS 4%

    thoughtworks · gocdMay 20, 2022

  • An issue was discovered in ThoughtWorks GoCD before 21.3.0.

    HighCVSS 8.8No exploitEPSS 3%

    thoughtworks · gocdApr 14, 2022

  • Compromised agents may be able to execute remote code on GoCD Server

    HighCVSS 8.8No exploitEPSS 2%

    thoughtworks · gocdOct 14, 2022

  • In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup

    HighCVSS 8.8No exploitEPSS 1%

    thoughtworks · gocdApr 1, 2021

  • An issue was discovered in ThoughtWorks GoCD before 21.3.0.

    HighCVSS 7.5No exploitEPSS 2%

    thoughtworks · gocdApr 14, 2022

  • Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames

    MediumCVSS 6.8No exploitEPSS 2%

    thoughtworks · gocdApr 11, 2022

  • GoCD server secret encryption/decryption key leaked to agents during material serialization

    MediumCVSS 6.5No exploitEPSS 1%

    thoughtworks · gocdOct 14, 2022

  • Malicious agent may be able to impersonate another agent in GoCD

    MediumCVSS 6.5No exploitEPSS 1%

    thoughtworks · gocdOct 14, 2022

  • An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.

    MediumCVSS 6.5No exploitEPSS 1%

    thoughtworks · node-worker-threads-poolAug 11, 2023

  • Reflected XSS in GoCD

    MediumCVSS 6.1No exploitEPSS 1%

    thoughtworks · gocdMay 20, 2022

  • GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-up

    MediumCVSS 6.1No exploitEPSS 0%

    thoughtworks · gocdMay 14, 2024

  • GoCD API authentication of user access tokens subject to timing attack during comparison

    MediumCVSS 5.9No exploitEPSS 1%

    thoughtworks · gocdOct 14, 2022

  • GoCD Windows installations outside default location inadequately restrict installation file permissions

    MediumCVSS 5.5No exploitEPSS 0%

    thoughtworks · gocdSep 7, 2022

  • An issue was discovered in ThoughtWorks GoCD before 21.3.0.

    MediumCVSS 5.4No exploitEPSS 1%

    thoughtworks · gocdApr 14, 2022

  • DOM-based XSS in GoCD

    MediumCVSS 5.4No exploitEPSS 1%

    thoughtworks · gocdMay 20, 2022

  • Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocd

    MediumCVSS 5.4No exploitEPSS 0%

    thoughtworks · gocdMar 27, 2023

  • Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocd

    MediumCVSS 4.4No exploitEPSS 0%

    thoughtworks · gocdMar 27, 2023

  • GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host access

    LowCVSS 3.8No exploitEPSS 1%

    thoughtworks · gocdJan 3, 2025

  • GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins

    LowCVSS 2.1No exploitEPSS 1%

    thoughtworks · gocdJan 3, 2025

  • GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionality

    LowCVSS 2.1No exploitEPSS 1%

    thoughtworks · gocdJan 3, 2025