PT-2024-29278 · Unknown · Woodpecker
D_K_Dev
+3
·
Published
2024-07-19
·
Updated
2024-11-15
·
CVE-2024-41122
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Woodpecker versions prior to 2.7.0
Description
The issue allows attackers to create malicious workflows that can lead to host takeover or secret leaks. This is possible because the server allows any user to trigger a pipeline run, and those workflows can either take over the host running the agent or extract secrets normally provided to plugins. The estimated number of potentially affected devices is not specified.
Recommendations
For versions prior to 2.7.0, upgrade to release version 2.7.0 to address the issue. As a temporary workaround, enable the "gated" repo feature and review each change upfront of running. There are no other known workarounds for this issue.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woodpecker