PT-2021-16854 · Gocd · Gocd
Published
2021-04-01
·
Updated
2021-04-06
·
CVE-2021-25924
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GoCD versions 19.6.0 through 21.1.0
Description
The issue is related to Cross-Site Request Forgery (CSRF) due to missing protection at the "/go/api/config/backup" endpoint. An attacker can trick a victim into clicking on a malicious link, potentially changing backup configurations or executing system commands in the
post backup script field.Recommendations
For GoCD versions 19.6.0 through 21.1.0, consider disabling access to the "/go/api/config/backup" endpoint until a patch is available. Restrict modifications to backup configurations and limit execution of system commands in the
post backup script field to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gocd