Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server
Package
Affected versions
>= 3.4.0, < 3.4.3
< 3.3.14
Patched versions
3.4.3
3.3.14
Description
Published by the National Vulnerability Database
Aug 30, 2021
Reviewed
Aug 30, 2021
Published to the GitHub Advisory Database
Sep 1, 2021
Last updated
Feb 1, 2023
Impact
A user with
admin
access to thesystem
resource type is potentially vulnerable to a CSRF attack that could cause the server to run untrusted code on all Rundeck editions.Patches
Available in Rundeck 3.4.3 and 3.3.14
Workarounds
Please visit https://rundeck.com/security for information about specific workarounds.
For more information
If you have any questions or comments about this advisory:
To report security issues to Rundeck please use the form at https://rundeck.com/security
References