Записи thoughtworks
24 опубликованных записей вендора thoughtworks.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-43290Эксплойта нет | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-22 | Критическая9,8 | — | 3,2 % | 14 апр. 2022 г. |
40В плане | CVE-2021-44659Эксплойта нет | Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achievethoughtworks · gocd · CWE-918 | Критическая9,8 | — | 2,5 % | 22 дек. 2021 г. |
38Наблюдать | CVE-2021-43287Proof of concept | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-200 | Высокая7,5 | — | 27,4 % | 14 апр. 2022 г. |
37Наблюдать | CVE-2024-56320Эксплойта нет | GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated userthoughtworks · gocd · CWE-285 | Критическая9,4 | — | 0,7 % | 3 янв. 2025 г. |
36Наблюдать | CVE-2022-29184Эксплойта нет | Command Injection/Argument Injection in GoCDthoughtworks · gocd · CWE-77 | Высокая8,8 | — | 3,8 % | 20 мая 2022 г. |
36Наблюдать | CVE-2021-43286Эксплойта нет | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-77 | Высокая8,8 | — | 2,9 % | 14 апр. 2022 г. |
36Наблюдать | CVE-2022-39311Эксплойта нет | Compromised agents may be able to execute remote code on GoCD Serverthoughtworks · gocd · CWE-502 | Высокая8,8 | — | 1,7 % | 14 окт. 2022 г. |
35Наблюдать | CVE-2021-25924Эксплойта нет | In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backupthoughtworks · gocd · CWE-352 | Высокая8,8 | — | 0,8 % | 1 апр. 2021 г. |
31Наблюдать | CVE-2021-43289Эксплойта нет | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-22 | Высокая7,5 | — | 2,3 % | 14 апр. 2022 г. |
28Наблюдать | CVE-2022-24832Эксплойта нет | Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernamesthoughtworks · gocd · CWE-74 | Средняя6,8 | — | 1,7 % | 11 апр. 2022 г. |
26Наблюдать | CVE-2022-39309Эксплойта нет | GoCD server secret encryption/decryption key leaked to agents during material serializationthoughtworks · gocd · CWE-200 | Средняя6,5 | — | 0,9 % | 14 окт. 2022 г. |
26Наблюдать | CVE-2022-39310Эксплойта нет | Malicious agent may be able to impersonate another agent in GoCDthoughtworks · gocd · CWE-284 | Средняя6,5 | — | 0,7 % | 14 окт. 2022 г. |
26Наблюдать | CVE-2021-29057Эксплойта нет | An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.thoughtworks · node-worker-threads-pool · CWE-400 | Средняя6,5 | — | 0,6 % | 11 авг. 2023 г. |
24Наблюдать | CVE-2022-29183Эксплойта нет | Reflected XSS in GoCDthoughtworks · gocd · CWE-79 | Средняя6,1 | — | 0,9 % | 20 мая 2022 г. |
24Наблюдать | CVE-2024-28866Эксплойта нет | GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-upthoughtworks · gocd · CWE-79 | Средняя6,1 | — | 0,4 % | 14 мая 2024 г. |
23Наблюдать | CVE-2022-39308Эксплойта нет | GoCD API authentication of user access tokens subject to timing attack during comparisonthoughtworks · gocd · CWE-208 | Средняя5,9 | — | 0,7 % | 14 окт. 2022 г. |
22Наблюдать | CVE-2022-36088Эксплойта нет | GoCD Windows installations outside default location inadequately restrict installation file permissionsthoughtworks · gocd · CWE-269 | Средняя5,5 | — | 0,2 % | 7 сент. 2022 г. |
21Наблюдать | CVE-2021-43288Эксплойта нет | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-79 | Средняя5,4 | — | 0,9 % | 14 апр. 2022 г. |
21Наблюдать | CVE-2022-29182Эксплойта нет | DOM-based XSS in GoCDthoughtworks · gocd · CWE-79 | Средняя5,4 | — | 0,8 % | 20 мая 2022 г. |
21Наблюдать | CVE-2023-28629Эксплойта нет | Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocdthoughtworks · gocd · CWE-79 | Средняя5,4 | — | 0,5 % | 27 мар. 2023 г. |
17Наблюдать | CVE-2023-28630Эксплойта нет | Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocdthoughtworks · gocd · CWE-532 | Средняя4,4 | — | 0,3 % | 27 мар. 2023 г. |
15Наблюдать | CVE-2024-56321Эксплойта нет | GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host accessthoughtworks · gocd · CWE-20 | Низкая3,8 | — | 0,5 % | 3 янв. 2025 г. |
8Наблюдать | CVE-2024-56324Эксплойта нет | GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group adminsthoughtworks · gocd · CWE-611 | Низкая2,1 | — | 0,8 % | 3 янв. 2025 г. |
8Наблюдать | CVE-2024-56322Эксплойта нет | GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionalitythoughtworks · gocd · CWE-611 | Низкая2,1 | — | 0,7 % | 3 янв. 2025 г. |
- CVE-2021-4329040В плане
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %thoughtworks · gocd14 апр. 2022 г.
- CVE-2021-4465940В плане
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %thoughtworks · gocd22 дек. 2021 г.
- CVE-2021-4328738Наблюдать
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
ВысокаяCVSS 7,5Proof of conceptEPSS 27 %thoughtworks · gocd14 апр. 2022 г.
- CVE-2024-5632037Наблюдать
GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %thoughtworks · gocd3 янв. 2025 г.
- CVE-2022-2918436Наблюдать
Command Injection/Argument Injection in GoCD
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %thoughtworks · gocd20 мая 2022 г.
- CVE-2021-4328636Наблюдать
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %thoughtworks · gocd14 апр. 2022 г.
- CVE-2022-3931136Наблюдать
Compromised agents may be able to execute remote code on GoCD Server
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %thoughtworks · gocd14 окт. 2022 г.
- CVE-2021-2592435Наблюдать
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %thoughtworks · gocd1 апр. 2021 г.
- CVE-2021-4328931Наблюдать
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %thoughtworks · gocd14 апр. 2022 г.
- CVE-2022-2483228Наблюдать
Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames
СредняяCVSS 6,8Эксплойта нетEPSS 2 %thoughtworks · gocd11 апр. 2022 г.
- CVE-2022-3930926Наблюдать
GoCD server secret encryption/decryption key leaked to agents during material serialization
СредняяCVSS 6,5Эксплойта нетEPSS 1 %thoughtworks · gocd14 окт. 2022 г.
- CVE-2022-3931026Наблюдать
Malicious agent may be able to impersonate another agent in GoCD
СредняяCVSS 6,5Эксплойта нетEPSS 1 %thoughtworks · gocd14 окт. 2022 г.
- CVE-2021-2905726Наблюдать
An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %thoughtworks · node-worker-threads-pool11 авг. 2023 г.
- CVE-2022-2918324Наблюдать
Reflected XSS in GoCD
СредняяCVSS 6,1Эксплойта нетEPSS 1 %thoughtworks · gocd20 мая 2022 г.
- CVE-2024-2886624Наблюдать
GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-up
СредняяCVSS 6,1Эксплойта нетEPSS 0 %thoughtworks · gocd14 мая 2024 г.
- CVE-2022-3930823Наблюдать
GoCD API authentication of user access tokens subject to timing attack during comparison
СредняяCVSS 5,9Эксплойта нетEPSS 1 %thoughtworks · gocd14 окт. 2022 г.
- CVE-2022-3608822Наблюдать
GoCD Windows installations outside default location inadequately restrict installation file permissions
СредняяCVSS 5,5Эксплойта нетEPSS 0 %thoughtworks · gocd7 сент. 2022 г.
- CVE-2021-4328821Наблюдать
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %thoughtworks · gocd14 апр. 2022 г.
- CVE-2022-2918221Наблюдать
DOM-based XSS in GoCD
СредняяCVSS 5,4Эксплойта нетEPSS 1 %thoughtworks · gocd20 мая 2022 г.
- CVE-2023-2862921Наблюдать
Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocd
СредняяCVSS 5,4Эксплойта нетEPSS 0 %thoughtworks · gocd27 мар. 2023 г.
- CVE-2023-2863017Наблюдать
Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocd
СредняяCVSS 4,4Эксплойта нетEPSS 0 %thoughtworks · gocd27 мар. 2023 г.
- CVE-2024-5632115Наблюдать
GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host access
НизкаяCVSS 3,8Эксплойта нетEPSS 1 %thoughtworks · gocd3 янв. 2025 г.
- CVE-2024-563248Наблюдать
GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %thoughtworks · gocd3 янв. 2025 г.
- CVE-2024-563228Наблюдать
GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionality
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %thoughtworks · gocd3 янв. 2025 г.