gocd Summary
Latest vulnerabilities published by gocd
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
GoCD is vulnerable to historical server configuration API authorization bypass
CVE-2026-52742GocdGocd5.1MEDIUMGoCD is vulnerable to credential exposure when admins insecurely configure material URLs
CVE-2026-55870GocdGocd2.3LOWGoCD is vulnerable to authorization bypass via material connection test APIs
CVE-2026-55625GocdGocd4.9MEDIUMGoCD is vulnerable to pipeline template view API authorization bypass
CVE-2026-52740GocdGocd5.3MEDIUMAuthorization Bypass in GoCD Continuous Delivery Server
CVE-2026-55060GocdGocd3.7LOWStored Cross-Site Scripting in GoCD by ThoughtWorks
CVE-2026-52741GocdGocd7.5HIGHCross-Site Scripting in GoCD Continuous Delivery Server
CVE-2026-68919GocdGocd7HIGHInformation Disclosure in GoCD Continuous Delivery Server
CVE-2026-52743GocdGocd4.3MEDIUMGoCD Potentially Vulnerable to Reflected Cross-Site Scripting Attacks
CVE-2024-28866GocdGocd6.1MEDIUMStored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocd
CVE-2023-28629GocdGocd5.4MEDIUMSensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocd
CVE-2023-28630GocdGocd4.2MEDIUMGoCD API authentication of user access tokens subject to timing attack during comparison
CVE-2022-39308GocdGocd6.5MEDIUMGoCD server secret encryption/decryption key leaked to agents during material serialization
CVE-2022-39309GocdGocd4.9MEDIUMMalicious agent may be able to impersonate another agent in GoCD
CVE-2022-39310GocdGocd4.9MEDIUMCompromised agents may be able to execute remote code on GoCD Server
CVE-2022-39311GocdGocd9.1CRITICALGoCD Windows installations outside default location inadequately restrict installation file permissions
CVE-2022-36088GocdGocd5MEDIUMCommand Injection/Argument Injection in GoCD
CVE-2022-29184GocdGocd8.8HIGHReflected XSS in GoCD
CVE-2022-29183GocdGocd4.3MEDIUMDOM-based XSS in GoCD
CVE-2022-29182GocdGocd4.3MEDIUMBundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames
CVE-2022-24832GocdGocd8.2HIGH