CVE-2026-105834: fallo de gravedad alta en rundeck
Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source
Publicada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1epss 0.4%
probabilidad de explotación
0.4%top 72% de las CVE
explotación observada
noninguna fuente lo reporta
Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
rundeck · rundeckCVEs relacionadas — rundeck
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-39132HIGHYAML deserialization can run untrusted codeEPSS 1.7%CVE-2020-11009MEDIUMIDOR can reveal execution data and logs to unauthorized user in RundeckEPSS 1.4%CVE-2022-29186CRITICALUse of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterpriseEPSS 1.2%CVE-2021-41112HIGHMissing Authorization in RundeckEPSS 0.7%CVE-2022-31044HIGHPlaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process AutomationEPSS 0.7%CVE-2021-41111MEDIUMAuthorization Bypass Through User-Controlled Key in RundeckEPSS 0.6%
Referencias
https://github.com/rundeck/rundeckhttps://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/resources/FileResourceModelSource.javahttps://github.com/rundeck/rundeck/commit/5ec3d0ad2ef19c2bf8f206f27d693ba8bf3337a4https://github.com/rundeck/rundeck/commit/a462982aa22bf350c9e121d213283ffaa7994b4ehttps://github.com/rundeck/rundeck/pull/10437https://github.com/rundeck/rundeck/releases/tag/v6.2.0https://www.vulncheck.com/advisories/rundeck-before-6.2.0-arbitrary-file-read-via-file-resource-model-source