An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-30230 An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:55:28.476Z

Reserved: 2021-11-02T00:00:00

Link: CVE-2021-43286

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-14T13:15:11.417

Modified: 2024-11-21T06:29:00.260

Link: CVE-2021-43286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.