« Volver al listado

Woodpecker-ci

Woodpecker-ci Woodpecker: vulnerabilidades y CVE

Woodpecker-ci Woodpecker tiene 9 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses5
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-61549Crítica (9)0.28%—15 sept 2026
Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in…
CVE-2026-58370Crítica (9.2)0.72%—30 jun 2026
Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, pipeline.Author is populated from the git commit author name (commit.author.name) carried in…
CVE-2026-58369Media (6.9)0.64%—30 jun 2026
Woodpecker before 3.15.0 registers the /api/orgs/lookup/*org_full_name endpoint without authentication middleware, and the LookupOrg handler unconditionally dereferences the session user (user.ForgeID, via…
CVE-2026-50141Alta (7.1)0.43%—18 jun 2026
Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by…
CVE-2025-13967Media (6.4)0.23%—9 ene 2026
The Woodpecker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_name' parameter of the [woodpecker-connector] shortcode in all versions up to, and including, 3.0.4 due to…
CVE-2024-41122Alta (8.8)0.62%—19 jul 2024
Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicious workflows: 1. Those workflows can either lead to a host takeover…
CVE-2024-41121Alta (8.8)0.74%—19 jul 2024
Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicious workflows: 1. Those workflows can either lead to a host takeover…
CVE-2023-40034Alta (8.1)0.88%—16 ago 2023
Woodpecker is a community fork of the Drone CI system. In affected versions an attacker can post malformed webhook data witch lead to an update of the repository data that can e.g. allow the takeover of an repo. This is…
CVE-2022-29947Media (6.1)0.68%—29 abr 2022
Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts2
  2. T1210 Exploitation of Remote Services2
  3. T1068 Exploitation for Privilege Escalation1
  4. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.