An issue was discovered in ThoughtWorks GoCD before 21.3...
Critical severity
Unreviewed
Published
Apr 15, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Apr 14, 2022
Published to the GitHub Advisory Database
Apr 15, 2022
Last updated
Jan 27, 2023
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control.
References