Vulnerability Description
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a malicious link which could change backup configurations or execute system commands in the post_backup_script field.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thoughtworks | Gocd | >= 19.6.0, < 21.2.0 |
Related Weaknesses (CWE)
References
- https://github.com/gocd/gocd/commit/7d0baab0d361c377af84994f95ba76c280048548PatchThird Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25924%2C
- https://github.com/gocd/gocd/commit/7d0baab0d361c377af84994f95ba76c280048548PatchThird Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25924%2C
FAQ
What is CVE-2021-25924?
CVE-2021-25924 is a vulnerability with a CVSS score of 8.8 (HIGH). In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a mal...
How severe is CVE-2021-25924?
CVE-2021-25924 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25924?
Check the references section above for vendor advisories and patch information. Affected products include: Thoughtworks Gocd.