Pagerduty
Pagerduty Rundeck: vulnerabilidades y CVE
Pagerduty Rundeck tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-48222 | Media (5.4) | 0.45% | — | 16 nov 2023 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in both Rundeck Open Source and Process Automation products could allow… |
| CVE-2023-47112 | Media (4.3) | 0.51% | — | 16 nov 2023 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in both Rundeck Open Source and Process Automation products could allow… |
| CVE-2022-31044 | Alta (7.5) | 0.67% | — | 15 jun 2022 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the… |
| CVE-2022-29186 | Crítica (9.8) | 1.2% | — | 20 may 2022 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public… |
| CVE-2021-41112 | Alta (8.1) | 0.75% | — | 28 feb 2022 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level… |
| CVE-2021-41111 | Media (5.4) | 0.56% | — | 28 feb 2022 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a… |
| CVE-2021-39133 | Media (6.8) | 0.45% | — | 30 ago 2021 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, a user with `admin` access to the `system` resource type is potentially… |
| CVE-2021-39132 | Alta (8.8) | 1.7% | — | 30 ago 2021 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, an authorized user can upload a zip-format plugin with a crafted plugin.yaml,… |
| CVE-2020-11009 | Media (6.5) | 1.4% | — | 29 abr 2020 | In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck… |
| CVE-2019-6804 | Media (6.1) | 5.3% | — | 25 ene 2019 | An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp. |