5.13.0-20250625
7 years ago
25 days ago
Known vulnerabilities in the org.rundeck:rundeck package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.rundeck:rundeck is an enable Self-Service Operations package which gives specific users access to your existing tools, services, and scripts. Affected versions of this package are vulnerable to Information Exposure. The Note:
This vulnerability affects those using any How to fix Information Exposure? Upgrade | [,4.2.2-20220615)[4.3.0-20220602,4.3.1-20220615) |
org.rundeck:rundeck is an enable Self-Service Operations package which gives specific users access to your existing tools, services, and scripts. Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF). A user with How to fix Cross-site Request Forgery (CSRF)? Upgrade | [0,3.3.14)[3.4.0,3.4.3) |
org.rundeck:rundeck is an enable Self-Service Operations package which gives specific users access to your existing tools, services, and scripts. Affected versions of this package are vulnerable to Information Exposure. Authenticated users can craft a request that reveals execution data and logs and job details that they are not authorized to see. Depending on the configuration and the way that Rundeck is used, this could result in anything between a high severity risk, or a very low risk. An authenticated user could craft a request to:
How to fix Information Exposure? Upgrade | [,3.2.6) |