CVE-2024-41122

HIGH

Woodpecker < 2.7.0 - Unauthenticated Pipeline Workflow Injection

Title source: llm
STIX 2.1

Description

Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicious workflows: 1. Those workflows can either lead to a host takeover that runs the agent executing the workflow. 2. Or allow to extract the secrets who would be normally provided to the plugins who's entrypoint are overwritten. This issue has been addressed in release version 2.7.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v3 7.5
EPSS 0.0062
EPSS Percentile 45.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-74
Status published
Products (3)
go.woodpecker-ci.org/woodpecker 0 - 2.7.0Go
woodpecker/v2 0 - 2.7.0Go
woodpecker-ci/woodpecker < 2.7.0
Published Jul 19, 2024
Tracked Since Feb 18, 2026