CVE-2026-105834: falha de alta gravidade em rundeck
Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source
Publicada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.1epss 0.4%
probabilidade de exploração
0.4%top 72% das CVEs
exploração observada
nãonenhuma fonte reporta
Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any absolute path. Attackers can retrieve file contents through editProjectNodeSourceFile or the apiSourceGetContent endpoint to obtain database passwords, LDAP bind credentials, and other projects' data.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
rundeck · rundeckCVEs relacionadas — rundeck
No mesmo produto, das mais perigosas para as menos.
CVE-2021-39132HIGHYAML deserialization can run untrusted codeEPSS 1.7%CVE-2020-11009MEDIUMIDOR can reveal execution data and logs to unauthorized user in RundeckEPSS 1.4%CVE-2022-29186CRITICALUse of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterpriseEPSS 1.2%CVE-2021-41112HIGHMissing Authorization in RundeckEPSS 0.7%CVE-2022-31044HIGHPlaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process AutomationEPSS 0.7%CVE-2021-41111MEDIUMAuthorization Bypass Through User-Controlled Key in RundeckEPSS 0.6%
Referências
https://github.com/rundeck/rundeckhttps://github.com/rundeck/rundeck/blob/v6.1.0/core/src/main/java/com/dtolabs/rundeck/core/resources/FileResourceModelSource.javahttps://github.com/rundeck/rundeck/commit/5ec3d0ad2ef19c2bf8f206f27d693ba8bf3337a4https://github.com/rundeck/rundeck/commit/a462982aa22bf350c9e121d213283ffaa7994b4ehttps://github.com/rundeck/rundeck/pull/10437https://github.com/rundeck/rundeck/releases/tag/v6.2.0https://www.vulncheck.com/advisories/rundeck-before-6.2.0-arbitrary-file-read-via-file-resource-model-source