VYPR

Vendor CVEs

GoCD

All CVEs

32 total · sorted by risk
  • CVE-2021-43290CriApr 14, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control.

  • CVE-2021-44659CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.03

    Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the…

  • CVE-2021-43286HigApr 14, 2022
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.

  • CVE-2021-25924HigApr 1, 2021
    risk 0.57cvss 8.8epss 0.01

    In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a malicious link which could change backup configurations or execute system commands…

  • CVE-2021-43287HigApr 14, 2022
    risk 0.51cvss 7.5epss 0.27

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

  • CVE-2021-43289HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, but does not control the filename.

  • CVE-2026-52741HigSep 21, 2026
    risk 0.42cvss —epss 0.01

    GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(.+). An attacker with commit access to a…

  • CVE-2026-68919HigSep 21, 2026
    risk 0.39cvss —epss 0.00

    GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage Detail, Job/Build Detail, Value Stream…

  • CVE-2026-52744MedSep 23, 2026
    risk 0.27cvss —epss 0.00

    GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to upstream dependency data. An authenticated user can retrieve inter-pipeline…

  • CVE-2026-52740MedSep 21, 2026
    risk 0.27cvss —epss 0.01

    GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with nonstandard HTTP method capitalization to…

  • CVE-2026-52742MedSep 21, 2026
    risk 0.26cvss —epss 0.01

    GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for groups they administer. The disclosed…

  • CVE-2026-55625MedSep 21, 2026
    risk 0.25cvss 4.9epss 0.01

    GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and pipeline-group context without sufficient…

  • CVE-2026-55632MedSep 23, 2026
    risk 0.21cvss 4.3epss 0.00

    GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without…

  • CVE-2026-52743MedSep 21, 2026
    risk 0.21cvss 4.3epss 0.00

    GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can guess job IDs and retrieve status for jobs…

  • CVE-2026-55060LowSep 21, 2026
    risk 0.17cvss 3.7epss 0.00

    GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source control child processes are running and…

  • CVE-2026-55870LowSep 21, 2026
    risk 0.08cvss —epss 0.01

    GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to regular authenticated users. Although GoCD recommends…

  • CVE-2024-56324HigJan 3, 2025
    risk 0.00cvss 7.1epss 0.01

    GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability…

  • CVE-2024-56322HigJan 3, 2025
    risk 0.00cvss 7.2epss 0.01

    GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which will be executed when…

  • CVE-2024-56321LowJan 3, 2025
    risk 0.00cvss 3.8epss 0.01

    GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or container as GoCD's user, rather than…

  • CVE-2024-56320HigJan 3, 2025
    risk 0.00cvss 8.8epss 0.01

    GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authenticated GoCD user with…

  • CVE-2024-28866LowMay 14, 2024
    risk 0.00cvss 3.1epss 0.00

    GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting vulnerability on the loading page displayed while GoCD is starting, via abuse of a `redirect_to` query parameter with inadequate…

  • CVE-2023-28630MedMar 27, 2023
    risk 0.00cvss 4.2epss 0.00

    GoCD is an open source continuous delivery server. In GoCD versions from 20.5.0 and below 23.1.0, if the server environment is not correctly configured by administrators to provide access to the relevant PostgreSQL or MySQL backup tools, the credentials for database access may…

  • CVE-2023-28629MedMar 27, 2023
    risk 0.00cvss 5.4epss 0.01

    GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configuration with a malicious pipeline label configuration can affect browser display of pipeline runs generated from that configuration.…

  • CVE-2022-39311CriOct 14, 2022
    risk 0.00cvss 9.1epss 0.02

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or compromised agent. The…

  • CVE-2022-39310MedOct 14, 2022
    risk 0.00cvss 4.9epss 0.01

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 can allow one authenticated agent to impersonate another agent, and thus receive work packages for…

  • CVE-2022-39309MedOct 14, 2022
    risk 0.00cvss 4.9epss 0.01

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 leak the symmetric key used to encrypt/decrypt any secure variables/secrets in GoCD configuration to…

  • CVE-2022-39308MedOct 14, 2022
    risk 0.00cvss 6.5epss 0.01

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions from 19.2.0 to 19.10.0 (inclusive) are subject to a timing attack in validation of access tokens due to use of regular…

  • CVE-2022-36088MedSep 7, 2022
    risk 0.00cvss 5.0epss 0.00

    GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malicious user with local access to the…

  • CVE-2022-29184HigMay 20, 2022
    risk 0.00cvss 8.8epss 0.04

    GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit or create pipeline materials or pipeline configuration repositories to get remote code execution capability on the GoCD server via…

  • CVE-2022-29183MedMay 20, 2022
    risk 0.00cvss 4.3epss 0.01

    GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the returned page. This could allow an attacker to trick a victim…

  • CVE-2022-29182MedMay 20, 2022
    risk 0.00cvss 4.3epss 0.01

    GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab. It is possible for a malicious script on a attacker-hosted…

  • CVE-2022-24832HigApr 11, 2022
    risk 0.00cvss 8.2epss 0.02

    GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly escape special characters when using the username to construct LDAP queries. While this does not directly allow arbitrary LDAP data…