Thoughtworks
Thoughtworks Gocd: vulnerabilidades y CVE
Thoughtworks Gocd tiene 33 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE33
Últimos 12 meses10
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55632 | Media (4.3) | 0.29% | — | 23 sept 2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its… |
| CVE-2026-52744 | Media (5.3) | 0.43% | — | 23 sept 2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream… |
| CVE-2026-68919 | Alta (7) | 0.48% | — | 21 sept 2026 | GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when… |
| CVE-2026-55870 | Baja (2.3) | 0.58% | — | 21 sept 2026 | GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to… |
| CVE-2026-55625 | Media (4.9) | 0.59% | — | 21 sept 2026 | GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary… |
| CVE-2026-55060 | Baja (3.7) | 0.41% | — | 21 sept 2026 | GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the… |
| CVE-2026-52743 | Media (4.3) | 0.40% | — | 21 sept 2026 | GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An… |
| CVE-2026-52742 | Media (5.1) | 0.71% | — | 21 sept 2026 | GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to… |
| CVE-2026-52741 | Alta (7.5) | 0.54% | — | 21 sept 2026 | GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing… |
| CVE-2026-52740 | Media (5.3) | 0.58% | — | 21 sept 2026 | GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send… |
| CVE-2024-56324 | Baja (2.1) | 0.78% | — | 3 ene 2025 | GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE)… |
| CVE-2024-56322 | Baja (2.1) | 0.70% | — | 3 ene 2025 | GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE)… |
| CVE-2024-56321 | Baja (3.8) | 0.55% | — | 3 ene 2025 | GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the… |
| CVE-2024-56320 | Crítica (9.4) | 0.74% | — | 3 ene 2025 | GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated… |
| CVE-2024-28866 | Media (6.1) | 0.42% | — | 14 may 2024 | GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting vulnerability on the loading page displayed while GoCD is starting,… |
| CVE-2023-28630 | Media (4.4) | 0.25% | — | 27 mar 2023 | GoCD is an open source continuous delivery server. In GoCD versions from 20.5.0 and below 23.1.0, if the server environment is not correctly configured by administrators to provide access to the relevant PostgreSQL or… |
| CVE-2023-28629 | Media (5.4) | 0.50% | — | 27 mar 2023 | GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configuration with a malicious pipeline label configuration can affect browser… |
| CVE-2022-39311 | Alta (8.8) | 1.7% | — | 14 oct 2022 | GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on… |
| CVE-2022-39310 | Media (6.5) | 0.70% | — | 14 oct 2022 | GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 can allow one authenticated agent to… |
| CVE-2022-39309 | Media (6.5) | 0.86% | — | 14 oct 2022 | GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 leak the symmetric key used to… |
| CVE-2022-39308 | Media (5.9) | 0.71% | — | 14 oct 2022 | GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions from 19.2.0 to 19.10.0 (inclusive) are subject to a timing… |
| CVE-2022-36088 | Media (5.5) | 0.23% | — | 7 sept 2022 | GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This… |
| CVE-2022-29184 | Alta (8.8) | 3.8% | — | 20 may 2022 | GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit or create pipeline materials or pipeline configuration repositories to… |
| CVE-2022-29183 | Media (6.1) | 0.86% | — | 20 may 2022 | GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the… |
| CVE-2022-29182 | Media (5.4) | 0.84% | — | 20 may 2022 | GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab.… |
| CVE-2021-43290 | Crítica (9.8) | 3.2% | — | 14 abr 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is… |
| CVE-2021-43289 | Alta (7.5) | 2.3% | — | 14 abr 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, but does not control the filename. |
| CVE-2021-43288 | Media (5.4) | 0.91% | — | 14 abr 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report. |
| CVE-2021-43286 | Alta (8.8) | 2.9% | — | 14 abr 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute… |
| CVE-2021-43287 | Alta (7.5) | 27% | — | 14 abr 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers. |