PT-2022-11365 · Rundeck · Rundeck
Fdevans
·
Published
2022-02-28
·
Updated
2022-03-10
·
CVE-2021-41112
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rundeck versions prior to 3.4.5
Description
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendars, without appropriate authorization. Modifying or removing calendars could cause Scheduled Jobs to execute, or not execute on desired calendar days. Severity depends on the trust level of authenticated users and the impact of running or not running scheduled jobs on days governed by calendar definitions.
Recommendations
For versions prior to 3.4.5, update to version 3.4.5 to resolve the issue. As a temporary workaround, consider restricting access to the calendar modification functionality to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rundeck