Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-56320 GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of acce… Gocd 24.5.0+ Fix from $1,9502025-01-03 HIGH 7.2 CVE-2024-56322 GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration rep… Gocd 24.5.0+ Fix from $1,9502025-01-03 HIGH 7.1 CVE-2024-56324 GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration f… Gocd 24.5.0+ Fix from $1,9502025-01-03 MEDIUM 6.1 CVE-2024-28866 GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting … Gocd 24.1.0+ Fix from $1,6002024-05-14 MEDIUM 6.5 CVE-2021-29057 An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service. Node Worker Threads Pool No fix yet Fix from $1,6002023-08-11 MEDIUM 5.4 CVE-2023-28629 GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configura… Gocd 23.1.0+ Fix from $1,6002023-03-27 HIGH 8.8 CVE-2022-39311 GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go… Gocd 21.1.0+ Fix from $1,9502022-10-14 MEDIUM 6.5 CVE-2022-39310 GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go… Gocd 21.1.0+ Fix from $1,6002022-10-14 MEDIUM 6.5 CVE-2022-39309 GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go… Gocd 21.1.0+ Fix from $1,6002022-10-14 MEDIUM 5.9 CVE-2022-39308 GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go… Gocd 19.11.0+ Fix from $1,6002022-10-14 MEDIUM 5.5 CVE-2022-36088 GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately rest… Gocd 22.2.0+ Fix from $1,6002022-09-07 HIGH 8.8 CVE-2022-29184 GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit … Gocd 22.1.0+ Fix from $1,9502022-05-20 MEDIUM 6.1 CVE-2022-29183 GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline co… Gocd 21.4.0+ Fix from $1,6002022-05-20 MEDIUM 5.4 CVE-2022-29182 GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-si… Gocd after 21.4.0 Fix from $1,6002022-05-20 CRITICAL 9.8 CVE-2021-43290 An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory… Gocd 21.3.0+ Fix from $2,3002022-04-14 HIGH 8.8 CVE-2021-43286 An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command… Gocd 21.3.0+ Fix from $1,9502022-04-14 HIGH 7.5 CVE-2021-43289 An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrar… Gocd 21.3.0+ Fix from $1,9502022-04-14 MEDIUM 5.4 CVE-2021-43288 An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job R… Gocd 21.3.0+ Fix from $1,6002022-04-14 HIGH 7.5 CVE-2021-43287EPSS 28% An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to t… Gocd 21.3.0+ Fix from $1,9502022-04-14 MEDIUM 6.8 CVE-2022-24832 GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly esc… Gocd 22.1.0+ Fix from $1,6002022-04-11 CRITICAL 9.8 CVE-2021-44659 Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server… Gocd No fix yet Fix from $2,3002021-12-22 HIGH 8.8 CVE-2021-25924 In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoin… Gocd 21.2.0+ Fix from $1,9502021-04-01