Authenticated users can view or delete jobs they do not have authorization for in Rundeck
CVE-2023-48222

8.1HIGH

Key Information:

Vendor

Rundeck

Status
Vendor
CVE Published:
16 November 2023

What is CVE-2023-48222?

An access control vulnerability in Rundeck's automation service allows authenticated users to potentially access restricted URLs. This flaw affects both the Open Source and Process Automation products, permitting unauthorized viewing and deletion of jobs. The issue has been resolved in version 4.17.3, and users are strongly advised to upgrade as there are no workarounds available.

Affected Version(s)

rundeck >= 4.12.0, < 4.17.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.