An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report.
References
Link Resource
https://blog.sonarsource.com/gocd-vulnerability-chain Exploit Patch Third Party Advisory
https://github.com/gocd/gocd/commit/f5c1d2aa9ab302a97898a6e4b16218e64fe8e9e4 Patch Third Party Advisory
https://www.gocd.org/releases/#21-3-0 Issue Tracking Release Notes Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-04-14T12:55:37

Updated: 2022-04-14T12:55:37

Reserved: 2021-11-02T00:00:00


Link: CVE-2021-43288

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-04-14T13:15:11.460

Modified: 2022-04-22T20:41:14.843


Link: CVE-2021-43288

JSON object: View

cve-icon Redhat Information

No data.

CWE