VendorsPagerdutyrundeckall versions
Vulnerabilities

Pagerduty Rundeck

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2022-29186
Use of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterprise
Published 2022-05-20 · Modified
9.8EPSS 0.012
CVE-2021-39132
YAML deserialization can run untrusted code
Published 2021-08-30 · Modified
8.8EPSS 0.017
CVE-2021-41112
Missing Authorization in Rundeck
Published 2022-02-28 · Modified
8.1EPSS 0.007
CVE-2023-48222
Authenticated users can view or delete jobs they do not have authorization for in Rundeck
Published 2023-11-16 · Modified
8.1EPSS 0.004
CVE-2022-31044
Plaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process Automation
Published 2022-06-15 · Modified
7.5EPSS 0.007
CVE-2021-39133
Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server
Published 2021-08-30 · Modified
7.2EPSS 0.005
CVE-2020-11009
IDOR can reveal execution data and logs to unauthorized user in Rundeck
Published 2020-04-29 · Modified
6.5EPSS 0.014
CVE-2021-41111
Authorization Bypass Through User-Controlled Key in Rundeck
Published 2022-02-28 · Modified
6.4EPSS 0.006
CVE-2019-6804
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp.
Published 2019-01-25 · Modified
6.11 PoCEPSS 0.053
CVE-2023-47112
Authenticated users can view job names and groups they do not have authorization to view in Rundeck
Published 2023-11-16 · Modified
4.3EPSS 0.005