QID 376673
Date Published: 2022-06-21
QID 376673: Rundeck Use of Hard-coded Credentials Vulnerability
Rundeck, a PagerDuty company, delivers the leading Runbook Automation platform for Enterprise IT.
Affected Versions:
Rundeck before version 4.1.0
QID Detection Logic (authenticated):
Check if any docker instances of rundeck is running and then extract the version number using the Name of the Image. This checks for vulnerable version of Rundeck.
Note: This QID only impacts Rundeck Docker instances.
Docker images contained a pre-generated SSH key pair. If the id_rsa.pub public key of the key pair was copied to authorized_keys files on remote hosts, those hosts would allow access to anyone with the exposed private key.
Solution
Upgrade to the 4.1.x or latest patch. Refer to Rundeck Downloads to address this issue and obtain more information.Workaround:
Refer the advisory for Workaround related information Rundeck Advisory
Vendor References
- Rundeck Advisory -
github.com/rundeck/rundeck/security/advisories/GHSA-qxjx-xr2m-hgqx
CVEs related to QID 376673
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qxjx-xr2m-hgqx |
|