Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, a user with `admin` access to the `system` resource type is potentially vulnerable to a CSRF attack that could cause the server to run untrusted code on all Rundeck editions. Patches are available in Rundeck versions 3.4.3 and 3.3.14.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1964 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, a user with `admin` access to the `system` resource type is potentially vulnerable to a CSRF attack that could cause the server to run untrusted code on all Rundeck editions. Patches are available in Rundeck versions 3.4.3 and 3.3.14. |
Github GHSA |
GHSA-3jmw-c69h-426c | Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T01:58:17.706Z
Reserved: 2021-08-16T00:00:00.000Z
Link: CVE-2021-39133
No data.
Status : Modified
Published: 2021-08-30T20:15:07.730
Modified: 2024-11-21T06:18:39.390
Link: CVE-2021-39133
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA