Impact
Rundeck through 6.2.1 fails to enforce authorization on the importConfig and importNodesSources parameters of the project archive import endpoint. An attacker who has only the ability to trigger an import can supply crafted values that replace critical configuration files, including node executors and SSH key paths, thereby subverting job execution security controls.
Affected Systems
Rundeck versions up to 6.2.1 are affected. It is unclear whether earlier major releases also use the same import mechanism; administrators should verify whether their deployed version falls within the vulnerable range.
Risk and Exploitability
The vulnerability receives a CVSS score of 8.6, indicating high severity, yet the EPSS score is below 1%, suggesting low likelihood of active exploitation at present. It is not listed in CISA KEV. Attackers would exploit the project archive import REST endpoint after authenticating and obtaining import privileges, using the unchecked importConfig and importNodesSources parameters.
OpenCVE Enrichment