Vulnerabilities in rundeck
9 resultsVexday analysis
Rundeck apresenta perfil de risco moderado com 9 CVEs catalogadas, sendo 1 crítica, mas sem registros de exploração ativa em ambientes reais (KEV = 0). A fraqueza predominante é controle de acesso inadequado (CWE-862), sugerindo riscos de escalação de privilégio ou acesso não autorizado. Não há vulnerabilidades novas nos últimos 90 dias, indicando que o risco atual é estável e não emergente.
CVE-2021-39132HIGHYAML deserialization can run untrusted codeEPSS 1.4%CVE-2020-11009MEDIUMIDOR can reveal execution data and logs to unauthorized user in RundeckEPSS 1.4%CVE-2022-29186CRITICALUse of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterpriseEPSS 1.2%CVE-2021-41112HIGHMissing Authorization in RundeckEPSS 0.7%CVE-2022-31044HIGHPlaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process AutomationEPSS 0.6%CVE-2021-41111MEDIUMAuthorization Bypass Through User-Controlled Key in RundeckEPSS 0.6%CVE-2023-47112MEDIUMAuthenticated users can view job names and groups they do not have authorization to view in RundeckEPSS 0.5%CVE-2021-39133HIGHCross-Site Request Forgery (CSRF) can run untrusted code on Rundeck serverEPSS 0.5%CVE-2023-48222HIGHAuthenticated users can view or delete jobs they do not have authorization for in RundeckEPSS 0.4%