Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gocd HIGH 8.8
CVE-2024-56320

GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of acce…

Fix: 24.5.0+
Fix from $1,950 2025-01-03
Gocd HIGH 7.2
CVE-2024-56322

GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration rep…

Fix: 24.5.0+
Fix from $1,950 2025-01-03
Gocd HIGH 7.1
CVE-2024-56324

GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration f…

Fix: 24.5.0+
Fix from $1,950 2025-01-03
Gocd MEDIUM 6.1
CVE-2024-28866

GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting …

Fix: 24.1.0+
Fix from $1,600 2024-05-14
Node Worker Threads Pool MEDIUM 6.5
CVE-2021-29057

An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.

No fix yet
Fix from $1,600 2023-08-11
Gocd MEDIUM 5.4
CVE-2023-28629

GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerability, where pipeline configura…

Fix: 23.1.0+
Fix from $1,600 2023-03-27
Gocd HIGH 8.8
CVE-2022-39311

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go…

Fix: 21.1.0+
Fix from $1,950 2022-10-14
Gocd MEDIUM 6.5
CVE-2022-39310

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go…

Fix: 21.1.0+
Fix from $1,600 2022-10-14
Gocd MEDIUM 6.5
CVE-2022-39309

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go…

Fix: 21.1.0+
Fix from $1,600 2022-10-14
Gocd MEDIUM 5.9
CVE-2022-39308

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. Go…

Fix: 19.11.0+
Fix from $1,600 2022-10-14
Gocd MEDIUM 5.5
CVE-2022-36088

GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately rest…

Fix: 22.2.0+
Fix from $1,600 2022-09-07
Gocd HIGH 8.8
CVE-2022-29184

GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit …

Fix: 22.1.0+
Fix from $1,950 2022-05-20
Gocd MEDIUM 6.1
CVE-2022-29183

GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline co…

Fix: 21.4.0+
Fix from $1,600 2022-05-20
Gocd MEDIUM 5.4
CVE-2022-29182

GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-si…

Fix: after 21.4.0
Fix from $1,600 2022-05-20
Gocd CRITICAL 9.8
CVE-2021-43290

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory…

Fix: 21.3.0+
Fix from $2,300 2022-04-14
Gocd HIGH 8.8
CVE-2021-43286

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command…

Fix: 21.3.0+
Fix from $1,950 2022-04-14
Gocd HIGH 7.5
CVE-2021-43289

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrar…

Fix: 21.3.0+
Fix from $1,950 2022-04-14
Gocd MEDIUM 5.4
CVE-2021-43288

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job R…

Fix: 21.3.0+
Fix from $1,600 2022-04-14
Gocd HIGH 7.5
CVE-2021-43287EPSS 28%

An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to t…

Fix: 21.3.0+
Fix from $1,950 2022-04-14
Gocd MEDIUM 6.8
CVE-2022-24832

GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly esc…

Fix: 22.1.0+
Fix from $1,600 2022-04-11
Gocd CRITICAL 9.8
CVE-2021-44659

Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server…

No fix yet
Fix from $2,300 2021-12-22
Gocd HIGH 8.8
CVE-2021-25924

In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoin…

Fix: 21.2.0+
Fix from $1,950 2021-04-01