PT-2022-11365 · Rundeck · Rundeck

Fdevans

·

Published

2022-02-28

·

Updated

2022-03-10

·

CVE-2021-41112

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rundeck versions prior to 3.4.5
Description Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendars, without appropriate authorization. Modifying or removing calendars could cause Scheduled Jobs to execute, or not execute on desired calendar days. Severity depends on the trust level of authenticated users and the impact of running or not running scheduled jobs on days governed by calendar definitions.
Recommendations For versions prior to 3.4.5, update to version 3.4.5 to resolve the issue. As a temporary workaround, consider restricting access to the calendar modification functionality to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41112
GHSA-F68P-C9WH-J2Q8

Affected Products

Rundeck