İçeriğe atla
Noroxi

thoughtworks kayıtları

thoughtworks üreticisine ait 24 yayımlanmış kayıt.

Tüm kayıtlar

24 kayıt
  • CVE-2021-43290
    40Planlayın

    An issue was discovered in ThoughtWorks GoCD before 21.3.0.

    KritikCVSS 9,8İstismar yokEPSS %3

    thoughtworks · gocd14 Nis 2022

  • CVE-2021-44659
    40Planlayın

    Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve

    KritikCVSS 9,8İstismar yokEPSS %3

    thoughtworks · gocd22 Ara 2021

  • CVE-2021-43287
    38İzleyin

    An issue was discovered in ThoughtWorks GoCD before 21.3.0.

    YüksekCVSS 7,5Kavram kanıtıEPSS %27

    thoughtworks · gocd14 Nis 2022

  • CVE-2024-56320
    37İzleyin

    GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user

    KritikCVSS 9,4İstismar yokEPSS %1

    thoughtworks · gocd3 Oca 2025

  • CVE-2022-29184
    36İzleyin

    Command Injection/Argument Injection in GoCD

    YüksekCVSS 8,8İstismar yokEPSS %4

    thoughtworks · gocd20 May 2022

  • CVE-2021-43286
    36İzleyin

    An issue was discovered in ThoughtWorks GoCD before 21.3.0.

    YüksekCVSS 8,8İstismar yokEPSS %3

    thoughtworks · gocd14 Nis 2022

  • CVE-2022-39311
    36İzleyin

    Compromised agents may be able to execute remote code on GoCD Server

    YüksekCVSS 8,8İstismar yokEPSS %2

    thoughtworks · gocd14 Eki 2022

  • CVE-2021-25924
    35İzleyin

    In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup

    YüksekCVSS 8,8İstismar yokEPSS %1

    thoughtworks · gocd1 Nis 2021

  • CVE-2021-43289
    31İzleyin

    An issue was discovered in ThoughtWorks GoCD before 21.3.0.

    YüksekCVSS 7,5İstismar yokEPSS %2

    thoughtworks · gocd14 Nis 2022

  • CVE-2022-24832
    28İzleyin

    Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames

    OrtaCVSS 6,8İstismar yokEPSS %2

    thoughtworks · gocd11 Nis 2022

  • CVE-2022-39309
    26İzleyin

    GoCD server secret encryption/decryption key leaked to agents during material serialization

    OrtaCVSS 6,5İstismar yokEPSS %1

    thoughtworks · gocd14 Eki 2022

  • CVE-2022-39310
    26İzleyin

    Malicious agent may be able to impersonate another agent in GoCD

    OrtaCVSS 6,5İstismar yokEPSS %1

    thoughtworks · gocd14 Eki 2022

  • CVE-2021-29057
    26İzleyin

    An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.

    OrtaCVSS 6,5İstismar yokEPSS %1

    thoughtworks · node-worker-threads-pool11 Ağu 2023

  • CVE-2022-29183
    24İzleyin

    Reflected XSS in GoCD

    OrtaCVSS 6,1İstismar yokEPSS %1

    thoughtworks · gocd20 May 2022

  • CVE-2024-28866
    24İzleyin

    GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-up

    OrtaCVSS 6,1İstismar yokEPSS %0

    thoughtworks · gocd14 May 2024

  • CVE-2022-39308
    23İzleyin

    GoCD API authentication of user access tokens subject to timing attack during comparison

    OrtaCVSS 5,9İstismar yokEPSS %1

    thoughtworks · gocd14 Eki 2022

  • CVE-2022-36088
    22İzleyin

    GoCD Windows installations outside default location inadequately restrict installation file permissions

    OrtaCVSS 5,5İstismar yokEPSS %0

    thoughtworks · gocd7 Eyl 2022

  • CVE-2021-43288
    21İzleyin

    An issue was discovered in ThoughtWorks GoCD before 21.3.0.

    OrtaCVSS 5,4İstismar yokEPSS %1

    thoughtworks · gocd14 Nis 2022

  • CVE-2022-29182
    21İzleyin

    DOM-based XSS in GoCD

    OrtaCVSS 5,4İstismar yokEPSS %1

    thoughtworks · gocd20 May 2022

  • CVE-2023-28629
    21İzleyin

    Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocd

    OrtaCVSS 5,4İstismar yokEPSS %0

    thoughtworks · gocd27 Mar 2023

  • CVE-2023-28630
    17İzleyin

    Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocd

    OrtaCVSS 4,4İstismar yokEPSS %0

    thoughtworks · gocd27 Mar 2023

  • CVE-2024-56321
    15İzleyin

    GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host access

    DüşükCVSS 3,8İstismar yokEPSS %1

    thoughtworks · gocd3 Oca 2025

  • GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins

    DüşükCVSS 2,1İstismar yokEPSS %1

    thoughtworks · gocd3 Oca 2025

  • GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionality

    DüşükCVSS 2,1İstismar yokEPSS %1

    thoughtworks · gocd3 Oca 2025