Go.Woodpecker-Ci.Org Woodpecker vulnerabilities
2 known vulnerabilities affecting go.woodpecker-ci.org/woodpecker.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-41121P3HIGH≥ 0, < 2.7.02024-07-19
CVE-2024-41121 [HIGH] CWE-22 Woodpecker's custom workspace allow to overwrite plugin entrypoint executable
Woodpecker's custom workspace allow to overwrite plugin entrypoint executable
### Impact
The server allow to create any user who can trigger a pipeline run malicious workflows:
- Those workflows can either lead to a host takeover that runs the agent executing the workflow.
- Or allow to extract the secrets who would be normally provided to the plugins who's entrypoint are overwritten.
###
ghsaosv
CVE-2024-41122P3MEDIUM≥ 0, < 2.7.02024-07-19
CVE-2024-41122 [MEDIUM] CWE-74 Woodpecker's custom environment variables allow to alter execution flow of plugins
Woodpecker's custom environment variables allow to alter execution flow of plugins
### Impact
The server allow to create any user who can trigger a pipeline run malicious workflows:
- Those workflows can either lead to a host takeover that runs the agent executing the workflow.
- Or allow to extract the secrets who would be normally provided to the plugins who's entrypoint are overw
ghsaosv