Known Vulnerabilities for Rundeck by Jenkins
Listed below are 7 of the newest known vulnerabilities associated with "Rundeck" by "Jenkins".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-41234 json | Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users wi... | 8.8 - HIGH | 2022-09-21 | 2023-11-01 |
| CVE-2022-41233 json | Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, allowi... | 4.3 - MEDIUM | 2022-09-21 | 2023-11-01 |
| CVE-2022-30956 json | Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored... | 5.4 - MEDIUM | 2022-05-17 | 2023-11-02 |
| CVE-2020-2144 json | Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | 7.1 - HIGH | 2020-03-09 | 2023-10-25 |
| CVE-2019-16556 json | Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xm... | 6.5 - MEDIUM | 2019-12-17 | 2023-10-25 |
| CVE-2019-10455 json | A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an attacker-... | 4.3 - MEDIUM | 2019-10-16 | 2023-10-25 |
| CVE-2019-10454 json | A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specified URL... | 4.3 - MEDIUM | 2019-10-16 | 2023-10-25 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jenkins | Rundeck | 3.6.6 | |||
| Application | Jenkins | Rundeck | 3.6.5 | |||
| Application | Jenkins | Rundeck | 3.6.4 | |||
| Application | Jenkins | Rundeck | 3.6.3 | |||
| Application | Jenkins | Rundeck | 3.6.2 | |||
| Application | Jenkins | Rundeck | 3.6.1 | |||
| Application | Jenkins | Rundeck | 3.6.0 | |||
| Application | Jenkins | Rundeck | 3.5.4 | |||
| Application | Jenkins | Rundeck | 3.5.3 | |||
| Application | Jenkins | Rundeck | 3.5.2 | |||
| Application | Jenkins | Rundeck | 3.5.1 | |||
| Application | Jenkins | Rundeck | 3.5 | |||
| Application | Jenkins | Rundeck | 3.4 | |||
| Application | Jenkins | Rundeck | 3.3 | |||
| Application | Jenkins | Rundeck | 3.2 | |||
| Application | Jenkins | Rundeck | 3.1 | |||
| Application | Jenkins | Rundeck | 3.0 | |||
| Application | Jenkins | Rundeck | 2.9 | |||
| Application | Jenkins | Rundeck | 2.8 | |||
| Application | Jenkins | Rundeck | 2.7 |