Vulnerabilities > Thoughtworks

DATE CVE VULNERABILITY TITLE RISK
2022-05-20 CVE-2022-29183 Cross-site Scripting vulnerability in Thoughtworks Gocd
GoCD is a continuous delivery server.
network
low complexity
thoughtworks CWE-79
6.1
2022-04-14 CVE-2021-43286 Command Injection vulnerability in Thoughtworks Gocd
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
network
low complexity
thoughtworks CWE-77
8.8
2022-04-14 CVE-2021-43288 Cross-site Scripting vulnerability in Thoughtworks Gocd
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
network
low complexity
thoughtworks CWE-79
5.4
2022-04-14 CVE-2021-43289 Path Traversal vulnerability in Thoughtworks Gocd
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
network
low complexity
thoughtworks CWE-22
7.5
2022-04-14 CVE-2021-43290 Path Traversal vulnerability in Thoughtworks Gocd
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
network
low complexity
thoughtworks CWE-22
critical
9.8
2022-04-14 CVE-2021-43287 Information Exposure vulnerability in Thoughtworks Gocd
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
network
low complexity
thoughtworks CWE-200
7.5
2022-04-11 CVE-2022-24832 Injection vulnerability in Thoughtworks Gocd
GoCD is an open source a continuous delivery server.
network
high complexity
thoughtworks CWE-74
6.8
2021-12-22 CVE-2021-44659 Server-Side Request Forgery (SSRF) vulnerability in Thoughtworks Gocd 21.3.0
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF).
network
low complexity
thoughtworks CWE-918
critical
9.8
2021-04-01 CVE-2021-25924 Cross-Site Request Forgery (CSRF) vulnerability in Thoughtworks Gocd
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint.
network
low complexity
thoughtworks CWE-352
8.8