CVE-2021-44659
Dashboard / Vulnerabilities / CVE-2021-44659
CVE-2021-44659
Published: 22 Dec 2021Last Modified: 8 Jul 2026
Summary:
Details: Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the product's design allows an admin to configure outbound requests
References: https://www.gocd.org/, https://github.com/Mesh3l911/CVE-2021-44659, https://github.com/gocd/gocd, https://youtu.be/WW_a3znugl0
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 4c4bb4780eb0d3fc4cacfc4cfcc0b07e2eaf0595
Fixed -None
Affected versions
21.3.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
