CVE-2023-47112
- EPSS 0.21%
- Published 16.11.2023 22:15:28
- Last modified 21.11.2024 08:29:48
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in both Rundeck Open Source and Process Automation products could allow authenticated users to access the U...
CVE-2023-48222
- EPSS 0.24%
- Published 16.11.2023 22:15:28
- Last modified 21.11.2024 08:31:14
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in both Rundeck Open Source and Process Automation products could allow authenticated users to access the U...
CVE-2022-31044
- EPSS 0.15%
- Published 15.06.2022 19:15:11
- Last modified 21.11.2024 07:03:46
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storag...
CVE-2022-29186
- EPSS 0.29%
- Published 20.05.2022 21:15:10
- Last modified 21.11.2024 06:58:40
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key of the keypair was copied to ...
CVE-2021-41111
- EPSS 0.14%
- Published 28.02.2022 20:15:08
- Last modified 21.11.2024 06:25:29
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a request to reveal Webhook defin...
CVE-2021-41112
- EPSS 0.21%
- Published 28.02.2022 20:15:08
- Last modified 21.11.2024 06:25:29
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendars, without appropriate authori...
CVE-2021-39132
- EPSS 0.48%
- Published 30.08.2021 20:15:07
- Last modified 21.11.2024 06:18:39
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, an authorized user can upload a zip-format plugin with a crafted plugin.yaml, or a crafted aclpolicy yaml fil...
CVE-2021-39133
- EPSS 0.15%
- Published 30.08.2021 20:15:07
- Last modified 21.11.2024 06:18:39
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, a user with `admin` access to the `system` resource type is potentially vulnerable to a CSRF attack that coul...
CVE-2020-11009
- EPSS 0.5%
- Published 29.04.2020 17:15:11
- Last modified 21.11.2024 04:56:34
In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck is used, this could result in a...
CVE-2019-6804
- EPSS 9.07%
- Published 25.01.2019 05:29:00
- Last modified 21.11.2024 04:47:11
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp.