PT-2024-29277 · Unknown · Woodpecker

D_K_Dev

+3

·

Published

2024-07-19

·

Updated

2024-10-03

·

CVE-2024-41121

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Woodpecker versions prior to 2.7.0
Description The server allows any user to create and trigger malicious workflows, potentially leading to a host takeover or extraction of secrets normally provided to plugins. This issue can be exploited through the custom workspace feature, which allows overwriting plugin entrypoint executables.
Recommendations For versions prior to 2.7.0, upgrade to release version 2.7.0 to address the issue. As a temporary workaround, enable the "gated" repo feature and review each change upfront to minimize the risk of exploitation. Restrict access to the custom workspace feature to prevent overwriting plugin entrypoint executables until the issue is resolved.

Exploit

Fix

Path traversal

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-41121
GHSA-XW35-RRCP-G7XM
GO-2024-2999

Affected Products

Woodpecker