PT-2022-20482 · Rundeck · Rundeck

Published

2022-06-15

·

Updated

2022-06-24

·

CVE-2022-31044

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rundeck versions 4.2.0 through 4.2.1
Description The Key Storage converter plugin mechanism was not enabled correctly, resulting in the use of the encryption layer for Key Storage possibly not working. Any credentials created or overwritten using the affected versions might result in them being written in plaintext to the backend storage. This affects those using any Storage Converter plugin.
Recommendations For Rundeck versions 4.2.0 and 4.2.1, to prevent plaintext credentials from being stored, write access to key storage can be disabled via ACLs. After upgrading to Rundeck 4.3.1 or later, write access can be restored. Upgrade to Rundeck 4.3.2, 4.2.3, or 4.4.0 and later releases, which have fixed the code and will re-encrypt any plain text values upon upgrade.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31044
GHSA-HPRF-RRWQ-JM5C

Affected Products

Rundeck