Vulnerabilities > Thoughtworks > Gocd > 20.10.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-04-01 | CVE-2021-25924 | Cross-Site Request Forgery (CSRF) vulnerability in Thoughtworks Gocd In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. | 8.8 |