Rundeck through 6.2.1 Authorization Bypass via Project Import
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
rundeck · rundeckReferences
https://github.com/rundeck/rundeckhttps://github.com/rundeck/rundeck/blob/v5.20.1/rundeckapp/grails-app/controllers/rundeck/controllers/ProjectController.groovy#L3395-L3506https://github.com/rundeck/rundeck/issues/10459https://www.vulncheck.com/advisories/rundeck-through-6.2.1-authorization-bypass-via-project-import