CVE-2024-41122High· 7.5▾ TwilightWoodpecker's custom environment variables allow to alter execution flow of plugins
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
The server allow to create any user who can trigger a pipeline run malicious workflows:
https://github.com/woodpecker-ci/woodpecker/pull/3909 https://github.com/woodpecker-ci/woodpecker/pull/3934
Is there a way for users to fix or remediate the vulnerability without upgrading? Enable the "gated" repo feature and review each change upfront of running
go.woodpecker-ci.org/woodpecker/v2 < 2.7.0go.woodpecker-ci.org/woodpecker < 2.7.0Upgrade to a patched release:
go.woodpecker-ci.org/woodpecker/v2 2.7.0go.woodpecker-ci.org/woodpecker 2.7.0Connected by shared product, vendor, weakness, or advisory.