Описание
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the product's design allows an admin to configure outbound requests
Ссылки
- Broken LinkExploitThird Party Advisory
- ProductThird Party Advisory
- ProductVendor Advisory
- ExploitThird Party Advisory
- Broken LinkExploitThird Party Advisory
- ProductThird Party Advisory
- ProductVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:thoughtworks:gocd:21.3.0:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.0199
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 9.8
github
около 4 лет назад
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF)
EPSS
Процентиль: 83%
0.0199
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-918