Security readout for executives and security teams
Plain-English summary
CVE-2021-43289 affects ThoughtWorks GoCD before 21.3.0. If an attacker has already compromised a GoCD agent, they can place a malicious file into an arbitrary directory on the GoCD server. They do not control the filename, but the server-side write capability is serious for CI/CD environments.
Executive priority
Prioritize remediation where GoCD supports production delivery, sensitive code, or privileged deployment workflows. The issue requires prior agent compromise, but CI/CD servers are high-value control points.
Technical view
The vulnerability is an arbitrary directory file-upload issue from a compromised GoCD agent to the GoCD server. The CVE states the attacker cannot control the uploaded filename. Public references point to GoCD 21.3.0 release material, fixing commits, and SonarSource’s vulnerability-chain writeup.
Likely exposure
Exposure is limited to GoCD deployments before 21.3.0 where an attacker can compromise or control a GoCD agent. Internet exposure of the server alone is not established by the provided sources.
Exploitation context
The provided bundle does not show CISA KEV listing or confirmed active exploitation. The known attack context requires a compromised GoCD agent and can become more important when combined with other weaknesses in a broader chain.
Researcher notes
Key constraints matter: attacker needs a compromised agent and lacks filename control. Assess whether local deployment paths, permissions, or chained vulnerabilities could convert arbitrary-directory upload into code execution or persistence.
Mitigation direction
- Upgrade GoCD to version 21.3.0 or later.
- Review GoCD 21.3.0 release notes and linked commits.
- Treat compromised agents as server-risk events, not isolated build-node events.
- Restrict and monitor agent trust, registration, and access paths.
- Check vendor guidance before applying non-vendor workarounds.
Validation and detection
- Inventory GoCD server versions and confirm none are before 21.3.0.
- Identify all registered GoCD agents and their trust boundaries.
- Review recent agent compromise indicators and suspicious server file writes.
- Check GoCD server directories for unexpected new files.
- Confirm upgrade evidence through release or package records.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-43289 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.gocd.org/releases/#21-3-0CVE reference · x_refsource_MISC
- https://github.com/gocd/gocd/commit/4c4bb4780eb0d3fc4cacfc4cfcc0b07e2eaf0595CVE reference · x_refsource_MISC
- https://github.com/gocd/gocd/commit/c22e0428164af25d3e91baabd3f538a41cadc82fCVE reference · x_refsource_MISC
- https://blog.sonarsource.com/gocd-vulnerability-chainCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
