S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-43287 Scanner

CVE-2021-43287 scanner - Local File Inclusion vulnerability in ThoughtWorks GoCD

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-43287
7.5
CVSS

An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

ThoughtWorks GoCD is a popular continuous delivery tool designed to streamline the software development process. This platform enables users to automate builds, tests, and deployments while providing visibility and control over the entire process. ThoughtWorks GoCD is a trusted solution, commonly used by businesses across the globe to optimize and simplify time-consuming development tasks. 

CVE-2021-43287 is a severe vulnerability that has been detected in the ThoughtWorks GoCD platform. This particular vulnerability involves the business continuity add-on, which is enabled by default in the platform. CVE-2021-43287 is responsible for leaking all secrets known to the GoCD server to unauthenticated attackers, leading to a significant security risk for organizations that use the platform.

When exploited, the CVE-2021-43287 vulnerability can result in a potentially devastating outcome. Attackers can gain access to sensitive information, including passwords, credentials, and other confidential data, which can lead to data breaches or other malicious activities. This security risk can have a severe impact on businesses, including financial loss, reputational damage, and legal consequences.

s4e.io offers pro features that can help users easily and quickly learn about vulnerabilities in their digital assets, including ThoughtWorks GoCD. This platform provides comprehensive security assessments and proactive defense strategies to keep your organization's digital assets secure. By using s4e.io, you can gain peace of mind knowing that your organization is protected from vulnerabilities such as CVE-2021-43287.

 

REFERENCES

Solution Advice

Therefore, the following precautions can be taken to mitigate the risk of this vulnerability:

  • Upgrade ThoughtWorks GoCD to version 21.3.0 or higher immediately to ensure that the vulnerability is patched.
  • Disable the business continuity add-on until the vulnerable code has been fixed.
  • Limit access to the GoCD server and follow the principle of least privilege.
  • Implement security measures such as access controls, authentication, and encryption to protect sensitive information from unauthorized access.
  • Regularly monitor the system for unusual activity and anomalies that could indicate a security breach.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.