Rundeck Rundeck

Do you want an email whenever new security vulnerabilities are reported in Rundeck?

By the Year

In 2024 there have been 0 vulnerabilities in Rundeck . Rundeck did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 1 6.50
2019 1 6.10
2018 0 0.00

It may take a day or so for new Rundeck vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Rundeck Security Vulnerabilities

In Rundeck before version 3.2.6, authenticated users can craft a request

CVE-2020-11009 6.5 - Medium - April 29, 2020

In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck is used, this could result in anything between a high severity risk, or a very low risk. If access is tightly restricted and all users on the system have access to all projects, this is not really much of an issue. If access is wider and allows login for users that do not have access to any projects, or project access is restricted, there is a larger issue. If access is meant to be restricted and secrets, sensitive data, or intellectual property are exposed in Rundeck execution output and job data, the risk becomes much higher. This vulnerability is patched in version 3.2.6

Insecure Direct Object Reference / IDOR

An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13

CVE-2019-6804 6.1 - Medium - January 25, 2019

An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Pagerduty Rundeck or by Rundeck? Click the Watch button to subscribe.

Rundeck
Vendor

Rundeck
Product

subscribe