VYPR
Vendor

GoCD

Products
1
CVEs
32
Across products
32
Status
Private

Products

1

Recent CVEs

32
View all 32 CVEs →
  • CVE-2021-43290CriApr 14, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control.

  • CVE-2021-44659CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.03

    Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the…

  • CVE-2021-43286HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.

  • CVE-2021-25924HigApr 1, 2021
    risk 0.57cvss 8.8epss 0.01

    In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a malicious link which could change backup configurations or execute system commands…

  • CVE-2021-43287HigApr 14, 2022
    risk 0.51cvss 7.5epss 0.27

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

  • CVE-2021-43289HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, but does not control the filename.

  • CVE-2026-52741HigSep 21, 2026
    risk 0.42cvss —epss 0.01

    GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(.+). An attacker with commit access to a…

  • CVE-2026-68919HigSep 21, 2026
    risk 0.39cvss —epss 0.00

    GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage Detail, Job/Build Detail, Value Stream…

  • CVE-2026-52744MedSep 23, 2026
    risk 0.27cvss —epss 0.00

    GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline…

  • CVE-2026-52740MedSep 21, 2026
    risk 0.27cvss —epss 0.01

    GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with nonstandard HTTP method capitalization to…

  • CVE-2026-52742MedSep 21, 2026
    risk 0.26cvss —epss 0.01

    GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for groups they administer. The disclosed…

  • CVE-2026-55625MedSep 21, 2026
    risk 0.25cvss 4.9epss 0.01

    GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and pipeline-group context without sufficient…

  • CVE-2026-55632MedSep 23, 2026
    risk 0.21cvss 4.3epss 0.00

    GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without…

  • CVE-2026-52743MedSep 21, 2026
    risk 0.21cvss 4.3epss 0.00

    GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can guess job IDs and retrieve status for jobs…

  • CVE-2026-55060LowSep 21, 2026
    risk 0.17cvss 3.7epss 0.00

    GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and…

  • CVE-2026-55870LowSep 21, 2026
    risk 0.08cvss —epss 0.01

    GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to regular authenticated users. Although GoCD recommends…

  • CVE-2024-56324HigJan 3, 2025
    risk 0.00cvss 7.1epss 0.01

    GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability…

  • CVE-2024-56322HigJan 3, 2025
    risk 0.00cvss 7.2epss 0.01

    GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which will be executed when…

  • CVE-2024-56321LowJan 3, 2025
    risk 0.00cvss 3.8epss 0.01

    GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or container as GoCD's user, rather than…

  • CVE-2024-56320HigJan 3, 2025
    risk 0.00cvss 8.8epss 0.01

    GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authenticated GoCD user with…