CVE-2021-41111
CVE-2021-41111
Impact: Moderate
Affected Versions: < 3.4.5, < 3.3.15
Patched Versions: 3.4.5+, 3.3.15+
Impact
An authenticated user with authorization to read webhooks in one project, can craft a request to reveal Webhook definitions and tokens in another project. The user could use the revealed webhook tokens to trigger webhooks.
Severity depends on trust level of authenticated users, and whether any webhooks exist that trigger sensitive actions.
Patches
Patched in release 3.4.5+, 3.3.15+
Workarounds
None
For more information
If you have any questions or comments about this advisory:
Email us at security@rundeck.com
To report security issues to Rundeck please use the form at http://rundeck.com/security