thoughtworks records
24 published records for vendor thoughtworks.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-43290No exploit | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-22 | Critical9.8 | — | 3.2% | Apr 14, 2022 |
40Plan | CVE-2021-44659No exploit | Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achievethoughtworks · gocd · CWE-918 | Critical9.8 | — | 2.5% | Dec 22, 2021 |
38Monitor | CVE-2021-43287Proof of concept | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-200 | High7.5 | — | 27.4% | Apr 14, 2022 |
37Monitor | CVE-2024-56320No exploit | GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated userthoughtworks · gocd · CWE-285 | Critical9.4 | — | 0.7% | Jan 3, 2025 |
36Monitor | CVE-2022-29184No exploit | Command Injection/Argument Injection in GoCDthoughtworks · gocd · CWE-77 | High8.8 | — | 3.8% | May 20, 2022 |
36Monitor | CVE-2021-43286No exploit | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-77 | High8.8 | — | 2.9% | Apr 14, 2022 |
36Monitor | CVE-2022-39311No exploit | Compromised agents may be able to execute remote code on GoCD Serverthoughtworks · gocd · CWE-502 | High8.8 | — | 1.7% | Oct 14, 2022 |
35Monitor | CVE-2021-25924No exploit | In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backupthoughtworks · gocd · CWE-352 | High8.8 | — | 0.8% | Apr 1, 2021 |
31Monitor | CVE-2021-43289No exploit | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-22 | High7.5 | — | 2.3% | Apr 14, 2022 |
28Monitor | CVE-2022-24832No exploit | Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernamesthoughtworks · gocd · CWE-74 | Medium6.8 | — | 1.7% | Apr 11, 2022 |
26Monitor | CVE-2022-39309No exploit | GoCD server secret encryption/decryption key leaked to agents during material serializationthoughtworks · gocd · CWE-200 | Medium6.5 | — | 0.9% | Oct 14, 2022 |
26Monitor | CVE-2022-39310No exploit | Malicious agent may be able to impersonate another agent in GoCDthoughtworks · gocd · CWE-284 | Medium6.5 | — | 0.7% | Oct 14, 2022 |
26Monitor | CVE-2021-29057No exploit | An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.thoughtworks · node-worker-threads-pool · CWE-400 | Medium6.5 | — | 0.6% | Aug 11, 2023 |
24Monitor | CVE-2022-29183No exploit | Reflected XSS in GoCDthoughtworks · gocd · CWE-79 | Medium6.1 | — | 0.9% | May 20, 2022 |
24Monitor | CVE-2024-28866No exploit | GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-upthoughtworks · gocd · CWE-79 | Medium6.1 | — | 0.4% | May 14, 2024 |
23Monitor | CVE-2022-39308No exploit | GoCD API authentication of user access tokens subject to timing attack during comparisonthoughtworks · gocd · CWE-208 | Medium5.9 | — | 0.7% | Oct 14, 2022 |
22Monitor | CVE-2022-36088No exploit | GoCD Windows installations outside default location inadequately restrict installation file permissionsthoughtworks · gocd · CWE-269 | Medium5.5 | — | 0.2% | Sep 7, 2022 |
21Monitor | CVE-2021-43288No exploit | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-79 | Medium5.4 | — | 0.9% | Apr 14, 2022 |
21Monitor | CVE-2022-29182No exploit | DOM-based XSS in GoCDthoughtworks · gocd · CWE-79 | Medium5.4 | — | 0.8% | May 20, 2022 |
21Monitor | CVE-2023-28629No exploit | Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocdthoughtworks · gocd · CWE-79 | Medium5.4 | — | 0.5% | Mar 27, 2023 |
17Monitor | CVE-2023-28630No exploit | Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocdthoughtworks · gocd · CWE-532 | Medium4.4 | — | 0.3% | Mar 27, 2023 |
15Monitor | CVE-2024-56321No exploit | GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host accessthoughtworks · gocd · CWE-20 | Low3.8 | — | 0.5% | Jan 3, 2025 |
8Monitor | CVE-2024-56324No exploit | GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group adminsthoughtworks · gocd · CWE-611 | Low2.1 | — | 0.8% | Jan 3, 2025 |
8Monitor | CVE-2024-56322No exploit | GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionalitythoughtworks · gocd · CWE-611 | Low2.1 | — | 0.7% | Jan 3, 2025 |
- CVE-2021-4329040Plan
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
CriticalCVSS 9.8No exploitEPSS 3%thoughtworks · gocdApr 14, 2022
- CVE-2021-4465940Plan
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve
CriticalCVSS 9.8No exploitEPSS 3%thoughtworks · gocdDec 22, 2021
- CVE-2021-4328738Monitor
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
HighCVSS 7.5Proof of conceptEPSS 27%thoughtworks · gocdApr 14, 2022
- CVE-2024-5632037Monitor
GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user
CriticalCVSS 9.4No exploitEPSS 1%thoughtworks · gocdJan 3, 2025
- CVE-2022-2918436Monitor
Command Injection/Argument Injection in GoCD
HighCVSS 8.8No exploitEPSS 4%thoughtworks · gocdMay 20, 2022
- CVE-2021-4328636Monitor
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
HighCVSS 8.8No exploitEPSS 3%thoughtworks · gocdApr 14, 2022
- CVE-2022-3931136Monitor
Compromised agents may be able to execute remote code on GoCD Server
HighCVSS 8.8No exploitEPSS 2%thoughtworks · gocdOct 14, 2022
- CVE-2021-2592435Monitor
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup
HighCVSS 8.8No exploitEPSS 1%thoughtworks · gocdApr 1, 2021
- CVE-2021-4328931Monitor
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
HighCVSS 7.5No exploitEPSS 2%thoughtworks · gocdApr 14, 2022
- CVE-2022-2483228Monitor
Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames
MediumCVSS 6.8No exploitEPSS 2%thoughtworks · gocdApr 11, 2022
- CVE-2022-3930926Monitor
GoCD server secret encryption/decryption key leaked to agents during material serialization
MediumCVSS 6.5No exploitEPSS 1%thoughtworks · gocdOct 14, 2022
- CVE-2022-3931026Monitor
Malicious agent may be able to impersonate another agent in GoCD
MediumCVSS 6.5No exploitEPSS 1%thoughtworks · gocdOct 14, 2022
- CVE-2021-2905726Monitor
An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.
MediumCVSS 6.5No exploitEPSS 1%thoughtworks · node-worker-threads-poolAug 11, 2023
- CVE-2022-2918324Monitor
Reflected XSS in GoCD
MediumCVSS 6.1No exploitEPSS 1%thoughtworks · gocdMay 20, 2022
- CVE-2024-2886624Monitor
GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-up
MediumCVSS 6.1No exploitEPSS 0%thoughtworks · gocdMay 14, 2024
- CVE-2022-3930823Monitor
GoCD API authentication of user access tokens subject to timing attack during comparison
MediumCVSS 5.9No exploitEPSS 1%thoughtworks · gocdOct 14, 2022
- CVE-2022-3608822Monitor
GoCD Windows installations outside default location inadequately restrict installation file permissions
MediumCVSS 5.5No exploitEPSS 0%thoughtworks · gocdSep 7, 2022
- CVE-2021-4328821Monitor
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
MediumCVSS 5.4No exploitEPSS 1%thoughtworks · gocdApr 14, 2022
- CVE-2022-2918221Monitor
DOM-based XSS in GoCD
MediumCVSS 5.4No exploitEPSS 1%thoughtworks · gocdMay 20, 2022
- CVE-2023-2862921Monitor
Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocd
MediumCVSS 5.4No exploitEPSS 0%thoughtworks · gocdMar 27, 2023
- CVE-2023-2863017Monitor
Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocd
MediumCVSS 4.4No exploitEPSS 0%thoughtworks · gocdMar 27, 2023
- CVE-2024-5632115Monitor
GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host access
LowCVSS 3.8No exploitEPSS 1%thoughtworks · gocdJan 3, 2025
- CVE-2024-563248Monitor
GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins
LowCVSS 2.1No exploitEPSS 1%thoughtworks · gocdJan 3, 2025
- CVE-2024-563228Monitor
GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionality
LowCVSS 2.1No exploitEPSS 1%thoughtworks · gocdJan 3, 2025