Vulnerability Description
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thoughtworks | Gocd | < 21.3.0 |
Related Weaknesses (CWE)
References
- https://blog.sonarsource.com/gocd-vulnerability-chainExploitPatchThird Party Advisory
- https://github.com/gocd/gocd/commit/2b77b533abcbb79c8fc758dec9984305dc1ade42PatchThird Party Advisory
- https://github.com/gocd/gocd/commit/6fa9fb7a7c91e760f1adc2593acdd50f2d78676bPatchThird Party Advisory
- https://www.gocd.org/releases/#21-3-0Issue TrackingRelease NotesVendor Advisory
- https://blog.sonarsource.com/gocd-vulnerability-chainExploitPatchThird Party Advisory
- https://github.com/gocd/gocd/commit/2b77b533abcbb79c8fc758dec9984305dc1ade42PatchThird Party Advisory
- https://github.com/gocd/gocd/commit/6fa9fb7a7c91e760f1adc2593acdd50f2d78676bPatchThird Party Advisory
- https://www.gocd.org/releases/#21-3-0Issue TrackingRelease NotesVendor Advisory
FAQ
What is CVE-2021-43286?
CVE-2021-43286 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" fe...
How severe is CVE-2021-43286?
CVE-2021-43286 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43286?
Check the references section above for vendor advisories and patch information. Affected products include: Thoughtworks Gocd.