Описание
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the /go/api/config/backup endpoint. An attacker can trick a victim to click on a malicious link which could change backup configurations or execute system commands in the post_backup_script field.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 19.6.0 (включая) до 21.2.0 (исключая)
cpe:2.3:a:thoughtworks:gocd:*:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00928
Низкий
8.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-352
Связанные уязвимости
github
больше 3 лет назад
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a malicious link which could change backup configurations or execute system commands in the post_backup_script field.
EPSS
Процентиль: 76%
0.00928
Низкий
8.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-352