QID 376673

Date Published: 2022-06-21

QID 376673: Rundeck Use of Hard-coded Credentials Vulnerability

Rundeck, a PagerDuty company, delivers the leading Runbook Automation platform for Enterprise IT.

Affected Versions:
Rundeck before version 4.1.0

QID Detection Logic (authenticated):
Check if any docker instances of rundeck is running and then extract the version number using the Name of the Image. This checks for vulnerable version of Rundeck.

Note: This QID only impacts Rundeck Docker instances.

Docker images contained a pre-generated SSH key pair. If the id_rsa.pub public key of the key pair was copied to authorized_keys files on remote hosts, those hosts would allow access to anyone with the exposed private key.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Upgrade to the 4.1.x or latest patch. Refer to Rundeck Downloads to address this issue and obtain more information.Workaround:

    Refer the advisory for Workaround related information Rundeck Advisory

    CVEs related to QID 376673

    Software Advisories
    Advisory ID Software Component Link
    GHSA-qxjx-xr2m-hgqx URL Logo github.com/rundeck/rundeck/security/advisories/GHSA-qxjx-xr2m-hgqx