Security Advisory
CVE-2021-43289
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, but does not control the filename.