Gocd
Vendor:
First CVE: Apr 1, 2021 · Active for 5 years
23
Total CVEs
More Total CVEs than 95% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gocd over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2021
5 years ago
Most Recent CVE
Jan 3, 2025
568 days ago
CVE Severity & Scoring
Gocd23 CVEs
48%
39%
9%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (8.7%)
Network21 (91.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (91.3%)
High2 (8.7%)
Unknown0 (0.0%)
User Interaction
None17 (73.9%)
Unknown0 (0.0%)
Required6 (26.1%)
Privileges Required
Low11 (47.8%)
High3 (13.0%)
None9 (39.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43287HIGH An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticat | Apr 14, 2022 | 7.5 | 51 | NO | YES |
CVE-2021-43290CRITICAL An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can con | Apr 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-44659CRITICAL Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). N | Dec 22, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-29184HIGH GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit or create pipeline materials or | May 20, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-39311HIGH GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are | Oct 14, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-43286HIGH An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL | Apr 14, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-56320HIGH GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration | Jan 3, 2025 | 8.8 | 27 | NO | NO |
CVE-2021-25924HIGH In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a vict | Apr 1, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-43289HIGH An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, b | Apr 14, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-24832MEDIUM GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly escape special characters when usi | Apr 11, 2022 | 6.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Gocd
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 21.3.0 | 1 | 9.8 | 2.5% | 0 | 0 |