thoughtworks kayıtları
thoughtworks üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-43290İstismar yok | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-22 | Kritik9,8 | — | %3,2 | 14 Nis 2022 |
40Planlayın | CVE-2021-44659İstismar yok | Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achievethoughtworks · gocd · CWE-918 | Kritik9,8 | — | %2,5 | 22 Ara 2021 |
38İzleyin | CVE-2021-43287Kavram kanıtı | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-200 | Yüksek7,5 | — | %27,4 | 14 Nis 2022 |
37İzleyin | CVE-2024-56320İstismar yok | GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated userthoughtworks · gocd · CWE-285 | Kritik9,4 | — | %0,7 | 3 Oca 2025 |
36İzleyin | CVE-2022-29184İstismar yok | Command Injection/Argument Injection in GoCDthoughtworks · gocd · CWE-77 | Yüksek8,8 | — | %3,8 | 20 May 2022 |
36İzleyin | CVE-2021-43286İstismar yok | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-77 | Yüksek8,8 | — | %2,9 | 14 Nis 2022 |
36İzleyin | CVE-2022-39311İstismar yok | Compromised agents may be able to execute remote code on GoCD Serverthoughtworks · gocd · CWE-502 | Yüksek8,8 | — | %1,7 | 14 Eki 2022 |
35İzleyin | CVE-2021-25924İstismar yok | In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backupthoughtworks · gocd · CWE-352 | Yüksek8,8 | — | %0,8 | 1 Nis 2021 |
31İzleyin | CVE-2021-43289İstismar yok | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-22 | Yüksek7,5 | — | %2,3 | 14 Nis 2022 |
28İzleyin | CVE-2022-24832İstismar yok | Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernamesthoughtworks · gocd · CWE-74 | Orta6,8 | — | %1,7 | 11 Nis 2022 |
26İzleyin | CVE-2022-39309İstismar yok | GoCD server secret encryption/decryption key leaked to agents during material serializationthoughtworks · gocd · CWE-200 | Orta6,5 | — | %0,9 | 14 Eki 2022 |
26İzleyin | CVE-2022-39310İstismar yok | Malicious agent may be able to impersonate another agent in GoCDthoughtworks · gocd · CWE-284 | Orta6,5 | — | %0,7 | 14 Eki 2022 |
26İzleyin | CVE-2021-29057İstismar yok | An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.thoughtworks · node-worker-threads-pool · CWE-400 | Orta6,5 | — | %0,6 | 11 Ağu 2023 |
24İzleyin | CVE-2022-29183İstismar yok | Reflected XSS in GoCDthoughtworks · gocd · CWE-79 | Orta6,1 | — | %0,9 | 20 May 2022 |
24İzleyin | CVE-2024-28866İstismar yok | GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-upthoughtworks · gocd · CWE-79 | Orta6,1 | — | %0,4 | 14 May 2024 |
23İzleyin | CVE-2022-39308İstismar yok | GoCD API authentication of user access tokens subject to timing attack during comparisonthoughtworks · gocd · CWE-208 | Orta5,9 | — | %0,7 | 14 Eki 2022 |
22İzleyin | CVE-2022-36088İstismar yok | GoCD Windows installations outside default location inadequately restrict installation file permissionsthoughtworks · gocd · CWE-269 | Orta5,5 | — | %0,2 | 7 Eyl 2022 |
21İzleyin | CVE-2021-43288İstismar yok | An issue was discovered in ThoughtWorks GoCD before 21.3.0.thoughtworks · gocd · CWE-79 | Orta5,4 | — | %0,9 | 14 Nis 2022 |
21İzleyin | CVE-2022-29182İstismar yok | DOM-based XSS in GoCDthoughtworks · gocd · CWE-79 | Orta5,4 | — | %0,8 | 20 May 2022 |
21İzleyin | CVE-2023-28629İstismar yok | Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocdthoughtworks · gocd · CWE-79 | Orta5,4 | — | %0,5 | 27 Mar 2023 |
17İzleyin | CVE-2023-28630İstismar yok | Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocdthoughtworks · gocd · CWE-532 | Orta4,4 | — | %0,3 | 27 Mar 2023 |
15İzleyin | CVE-2024-56321İstismar yok | GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host accessthoughtworks · gocd · CWE-20 | Düşük3,8 | — | %0,5 | 3 Oca 2025 |
8İzleyin | CVE-2024-56324İstismar yok | GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group adminsthoughtworks · gocd · CWE-611 | Düşük2,1 | — | %0,8 | 3 Oca 2025 |
8İzleyin | CVE-2024-56322İstismar yok | GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionalitythoughtworks · gocd · CWE-611 | Düşük2,1 | — | %0,7 | 3 Oca 2025 |
- CVE-2021-4329040Planlayın
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
KritikCVSS 9,8İstismar yokEPSS %3thoughtworks · gocd14 Nis 2022
- CVE-2021-4465940Planlayın
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve
KritikCVSS 9,8İstismar yokEPSS %3thoughtworks · gocd22 Ara 2021
- CVE-2021-4328738İzleyin
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
YüksekCVSS 7,5Kavram kanıtıEPSS %27thoughtworks · gocd14 Nis 2022
- CVE-2024-5632037İzleyin
GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user
KritikCVSS 9,4İstismar yokEPSS %1thoughtworks · gocd3 Oca 2025
- CVE-2022-2918436İzleyin
Command Injection/Argument Injection in GoCD
YüksekCVSS 8,8İstismar yokEPSS %4thoughtworks · gocd20 May 2022
- CVE-2021-4328636İzleyin
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
YüksekCVSS 8,8İstismar yokEPSS %3thoughtworks · gocd14 Nis 2022
- CVE-2022-3931136İzleyin
Compromised agents may be able to execute remote code on GoCD Server
YüksekCVSS 8,8İstismar yokEPSS %2thoughtworks · gocd14 Eki 2022
- CVE-2021-2592435İzleyin
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup
YüksekCVSS 8,8İstismar yokEPSS %1thoughtworks · gocd1 Nis 2021
- CVE-2021-4328931İzleyin
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
YüksekCVSS 7,5İstismar yokEPSS %2thoughtworks · gocd14 Nis 2022
- CVE-2022-2483228İzleyin
Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames
OrtaCVSS 6,8İstismar yokEPSS %2thoughtworks · gocd11 Nis 2022
- CVE-2022-3930926İzleyin
GoCD server secret encryption/decryption key leaked to agents during material serialization
OrtaCVSS 6,5İstismar yokEPSS %1thoughtworks · gocd14 Eki 2022
- CVE-2022-3931026İzleyin
Malicious agent may be able to impersonate another agent in GoCD
OrtaCVSS 6,5İstismar yokEPSS %1thoughtworks · gocd14 Eki 2022
- CVE-2021-2905726İzleyin
An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.
OrtaCVSS 6,5İstismar yokEPSS %1thoughtworks · node-worker-threads-pool11 Ağu 2023
- CVE-2022-2918324İzleyin
Reflected XSS in GoCD
OrtaCVSS 6,1İstismar yokEPSS %1thoughtworks · gocd20 May 2022
- CVE-2024-2886624İzleyin
GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-up
OrtaCVSS 6,1İstismar yokEPSS %0thoughtworks · gocd14 May 2024
- CVE-2022-3930823İzleyin
GoCD API authentication of user access tokens subject to timing attack during comparison
OrtaCVSS 5,9İstismar yokEPSS %1thoughtworks · gocd14 Eki 2022
- CVE-2022-3608822İzleyin
GoCD Windows installations outside default location inadequately restrict installation file permissions
OrtaCVSS 5,5İstismar yokEPSS %0thoughtworks · gocd7 Eyl 2022
- CVE-2021-4328821İzleyin
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
OrtaCVSS 5,4İstismar yokEPSS %1thoughtworks · gocd14 Nis 2022
- CVE-2022-2918221İzleyin
DOM-based XSS in GoCD
OrtaCVSS 5,4İstismar yokEPSS %1thoughtworks · gocd20 May 2022
- CVE-2023-2862921İzleyin
Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocd
OrtaCVSS 5,4İstismar yokEPSS %0thoughtworks · gocd27 Mar 2023
- CVE-2023-2863017İzleyin
Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocd
OrtaCVSS 4,4İstismar yokEPSS %0thoughtworks · gocd27 Mar 2023
- CVE-2024-5632115İzleyin
GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host access
DüşükCVSS 3,8İstismar yokEPSS %1thoughtworks · gocd3 Oca 2025
- CVE-2024-563248İzleyin
GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins
DüşükCVSS 2,1İstismar yokEPSS %1thoughtworks · gocd3 Oca 2025
- CVE-2024-563228İzleyin
GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionality
DüşükCVSS 2,1İstismar yokEPSS %1thoughtworks · gocd3 Oca 2025