Thoughtworks maintains a modestly represented but concentrated vulnerability footprint centered on a small number of software products, most prominently the GoCD continuous-delivery platform and Node.js utility libraries. Its disclosures cluster around application and middleware-layer weakness classes including cross-site scripting, sensitive-information exposure, improper access control, path traversal, and command injection, reflecting the web-facing and script-execution surfaces of automation and developer-tooling software. A meaningful share of the vendor's vulnerabilities reach serious severity, though the overall profile is weighted toward moderate outcomes. Defenders should prioritize GoCD instances that face untrusted networks, given its role in build and deployment infrastructure, and treat the vendor's utility libraries as supply-chain dependencies requiring inventory and coordinated patching. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thoughtworks over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43287HIGH An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticat | Apr 14, 2022 | 7.5 | 51 | NO | YES |
CVE-2021-43290CRITICAL An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can con | Apr 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-44659CRITICAL Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). N | Dec 22, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-29184HIGH GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit or create pipeline materials or | May 20, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-39311HIGH GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are | Oct 14, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-43286HIGH An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL | Apr 14, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-56320HIGH GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration | Jan 3, 2025 | 8.8 | 27 | NO | NO |
CVE-2021-25924HIGH In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a vict | Apr 1, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-43289HIGH An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, b | Apr 14, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-24832MEDIUM GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly escape special characters when usi | Apr 11, 2022 | 6.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thoughtworks.
Media articles that mention a CVE ID that affects a product developed by Thoughtworks — matched by CVE ID, not by vendor name.