PT-2021-16854 · Gocd · Gocd

Published

2021-04-01

·

Updated

2021-04-06

·

CVE-2021-25924

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GoCD versions 19.6.0 through 21.1.0
Description The issue is related to Cross-Site Request Forgery (CSRF) due to missing protection at the "/go/api/config/backup" endpoint. An attacker can trick a victim into clicking on a malicious link, potentially changing backup configurations or executing system commands in the post backup script field.
Recommendations For GoCD versions 19.6.0 through 21.1.0, consider disabling access to the "/go/api/config/backup" endpoint until a patch is available. Restrict modifications to backup configurations and limit execution of system commands in the post backup script field to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25924

Affected Products

Gocd