VYPR

GoCD

by ThoughtWorks

CVEs (23)

  • CVE-2022-29183MedMay 20, 2022
    risk 0.00cvss 4.3epss 0.01

    GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the returned page. This could allow an attacker to trick a victim…

  • CVE-2022-29182MedMay 20, 2022
    risk 0.00cvss 4.3epss 0.01

    GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab. It is possible for a malicious script on a attacker-hosted…

  • CVE-2022-24832HigApr 11, 2022
    risk 0.00cvss 8.2epss 0.02

    GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly escape special characters when using the username to construct LDAP queries. While this does not directly allow arbitrary LDAP data…

Page 2 of 2