Aller au contenu

Fiche vulnérabilité

CVE-2021-44659 : faille critique thoughtworks gocd (CVSS 9.8)

Description

Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the product's design allows an admin to configure outbound requests

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
22 déc. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • thoughtworks gocd

Références

Rechercher une autre vulnérabilité dans la base CVE