Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jmw-c69h-426c

Опубликовано: 01 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server

Impact

A user with admin access to the system resource type is potentially vulnerable to a CSRF attack that could cause the server to run untrusted code on all Rundeck editions.

Patches

Available in Rundeck 3.4.3 and 3.3.14

Workarounds

Please visit https://rundeck.com/security for information about specific workarounds.

For more information

If you have any questions or comments about this advisory:

To report security issues to Rundeck please use the form at https://rundeck.com/security

Пакеты

Наименование

org.rundeck:rundeck-core

maven
Затронутые версииВерсия исправления

>= 3.4.0, < 3.4.3

3.4.3

Наименование

org.rundeck:rundeck-core

maven
Затронутые версииВерсия исправления

< 3.3.14

3.3.14

EPSS

Процентиль: 36%
0.00147
Низкий

7.2 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.2
nvd
больше 4 лет назад

Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, a user with `admin` access to the `system` resource type is potentially vulnerable to a CSRF attack that could cause the server to run untrusted code on all Rundeck editions. Patches are available in Rundeck versions 3.4.3 and 3.3.14.

EPSS

Процентиль: 36%
0.00147
Низкий

7.2 High

CVSS3

Дефекты

CWE-352