Vulnerabilities > CVE-2021-44659 - Server-Side Request Forgery (SSRF) vulnerability in Thoughtworks Gocd 21.3.0

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
thoughtworks
CWE-918
critical

Summary

Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the product's design allows an admin to configure outbound requests

Vulnerable Configurations

Part Description Count
Application
Thoughtworks
1

Common Weakness Enumeration (CWE)