CVE-2024-41122
Woodpecker-ci
CVE-2024-41122 is a critical vulnerability in Woodpecker CI/CD engine, allowing unauthorized user creation and malicious pipeline execution. This flaw permits attackers to potentially take over the host running the agent or extract sensitive secrets. While CVSS rates this as 8.8, the SOCRadar Vulnerability Risk Score (SVRS) is 77, indicating a high risk, near the threshold for critical severity. Upgrade to version 2.7.0 is strongly advised to mitigate this issue, as there are no known workarounds. The exploitation enables threat actors to execute workflows leading to significant data breaches and system compromise. Given that it's tagged "In The Wild", immediate patching is crucial to prevent potential attacks. This vulnerability underscores the importance of regular security audits and prompt patching in CI/CD environments.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.