Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 272 respecto a la semana anterior
Críticas / altas1349▲ 92 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.29% | — | Thoughtworks GocdAI | 23/9/2026 | 30/9/2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without requiring an administrator role. A… | |
| Aplazada | Media (5.3) | 0.43% | — | Thoughtworks GocdAI | 23/9/2026 | 30/9/2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline dependency hierarchy details and… | |
| Pendiente de análisis | Alta (7) | 0.48% | — | Thoughtworks GocdAI | 21/9/2026 | 25/9/2026 | GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage Detail, Job/Build Detail, Value Stream Map, and Pipeline History views. A user… | |
| Pendiente de análisis | Baja (2.3) | 0.58% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to regular authenticated users. Although GoCD recommends dedicated username and password fields or… | |
| Pendiente de análisis | Media (4.9) | 0.59% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and pipeline-group context without sufficient validation. A pipeline group… | |
| Pendiente de análisis | Baja (3.7) | 0.41% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and view command-line arguments, usernames,… | |
| Pendiente de análisis | Media (4.3) | 0.40% | — | Thoughtworks GocdAI | 21/9/2026 | 25/9/2026 | GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can guess job IDs and retrieve status for jobs in pipelines the user cannot otherwise… | |
| Pendiente de análisis | Media (5.1) | 0.71% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for groups they administer. The disclosed configuration can include agent… | |
| Pendiente de análisis | Alta (7.5) | 0.54% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(.+). An attacker with commit access to a tracked material can place URI or HTML… | |
| Pendiente de análisis | Media (5.3) | 0.58% | — | Thoughtworks GocdAI | 21/9/2026 | 24/9/2026 | GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with nonstandard HTTP method capitalization to retrieve a pipeline template by name… | |
| Aplazada | Crítica (10) | 1.7% | — | Argocd-mcpAI | 29/8/2026 | 23/9/2026 | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and… | |
| Pendiente de análisis | Crítica (9.9) | 0.70% | — | Argoproj ArgocdAIOpen Cluster Management Multicloud IntegrationsAI | 12/8/2026 | 27/8/2026 | A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary… | |
| Pendiente de análisis | Crítica (9.6) | 0.52% | — | Argoproj ArgocdAIRedhat Advanced Cluster ManagementAIRedhat Multicloud IntegrationsAI | 12/8/2026 | 27/8/2026 | A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure… | |
| Pendiente de análisis | Crítica (9.1) | 0.41% | — | Argoproj Argocd Image UpdaterAI | 15/4/2026 | 15/7/2026 | A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications… | |
| Aplazada | Crítica (9.1) | 0.69% | — | Redhat Openshift GitopsAIArgoproj ArgocdAI | 15/12/2025 | 30/9/2026 | A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run… | |
| Aplazada | Alta (8.2) | 0.22% | — | Redhat Openshift-gitops-operator-containerAIArgoproj ArgocdAI | 28/1/2025 | 26/6/2026 | A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out… | |
| Analizada | Baja (2.1) | 0.78% | — | Thoughtworks Gocd | 3/1/2025 | 17/6/2026 | GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability can result in additional attacks such as… | |
| Analizada | Baja (2.1) | 0.70% | — | Thoughtworks Gocd | 3/1/2025 | 17/6/2026 | GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which will be executed when GoCD periodically scans configuration… | |
| Analizada | Baja (3.8) | 0.55% | — | Thoughtworks Gocd | 3/1/2025 | 17/6/2026 | GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or container as GoCD's user, rather than pre-configured scripts. In practice the… | |
| Analizada | Crítica (9.4) | 0.74% | — | Thoughtworks Gocd | 3/1/2025 | 17/6/2026 | GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authenticated GoCD user with an existing GoCD user account could… | |
| Analizada | Media (6.1) | 0.42% | — | Thoughtworks Gocd | 14/5/2024 | 17/6/2026 | GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting vulnerability on the loading page displayed while GoCD is starting, via abuse of a `redirect_to` query parameter with inadequate validation. Attackers could theoretically… | |
| Modificada | Media (4.4) | 0.25% | — | Thoughtworks Gocd | 27/3/2023 | 17/6/2026 | GoCD is an open source continuous delivery server. In GoCD versions from 20.5.0 and below 23.1.0, if the server environment is not correctly configured by administrators to provide access to the relevant PostgreSQL or MySQL backup tools, the credentials for database access may be unintentionally leaked to admin alerts… | |
| Modificada | Media (5.4) | 0.50% | — | Thoughtworks Gocd | 27/3/2023 | 17/6/2026 | GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configuration with a malicious pipeline label configuration can affect browser display of pipeline runs generated from that configuration. An attacker that has permissions to… | |
| Modificada | Alta (8.8) | 1.7% | — | Thoughtworks Gocd | 14/10/2022 | 17/6/2026 | GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or compromised agent. The Spring RemoteInvocation endpoint exposed… | |
| Modificada | Media (6.5) | 0.70% | — | Thoughtworks Gocd | 14/10/2022 | 17/6/2026 | GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 can allow one authenticated agent to impersonate another agent, and thus receive work packages for other agents due to broken access control… |