QID 981317
QID 981317: Java (maven) Security Update for org.rundeck:rundeck-core (GHSA-3jmw-c69h-426c)
Security update has been released for org.rundeck:rundeck-core to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A user with `admin` access to the `system` resource type is potentially vulnerable to a CSRF attack that could cause the server to run untrusted code on all Rundeck editions.
Solution
Available in Rundeck 3.4.3 and 3.3.14Workaround:
Please visit [https://rundeck.com/security](https://rundeck.com/security) for information about specific workarounds.
Please visit [https://rundeck.com/security](https://rundeck.com/security) for information about specific workarounds.
Vendor References
- GHSA-3jmw-c69h-426c -
github.com/advisories/GHSA-3jmw-c69h-426c
CVEs related to QID 981317
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3jmw-c69h-426c | org.rundeck:rundeck-core |
|