Thoughtworks
24 known vulnerabilities
Top Products
GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edi
GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hi
GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to i
GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a re
An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a d
GoCD is an open source continuous delivery server. In GoCD versions from 20.5.0 and below 23.1.0, if the server environm
GoCD is an open source continuous delivery server. GoCD versions before 23.1.0 are vulnerable to a stored XSS vulnerabil
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to
GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users
GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting
GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Obje
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a ma
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a ma
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious J
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a Go
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default,
GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD
Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/
Frequently Asked Questions
How many CVEs affect Thoughtworks?
Thoughtworks has 24 CVE records in our database, including 3 critical and 9 high severity vulnerabilities.
What are the most severe Thoughtworks vulnerabilities?
Thoughtworks has 3 critical severity (CVSS 9.0+) and 9 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Thoughtworks vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Thoughtworks products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Thoughtworks Vulnerabilities
CyberStrike scans your infrastructure for Thoughtworks vulnerabilities and provides real-time remediation guidance.
Get Started