CVE-2021-43287
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.
7.5
CVSS
28.0%
EPSS (exploit prob.)
98th
EPSS percentile
2022-04-14
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| thoughtworks | gocd | < 21.3.0 |
Check a specific version with /api/v1/cve/match.
References
- https://blog.sonarsource.com/gocd-pre-auth-pipeline-takeover
- https://github.com/gocd/gocd/commit/41abc210ac4e8cfa184483c9ff1c0cc04fb3511c
- https://www.gocd.org/releases/#21-3-0
- https://blog.sonarsource.com/gocd-pre-auth-pipeline-takeover
- https://github.com/gocd/gocd/commit/41abc210ac4e8cfa184483c9ff1c0cc04fb3511c
- https://www.gocd.org/releases/#21-3-0
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-43287