CVE-2021-39133 affects Rundeck versions prior to 3.3.14 and 3.4.3, where an authenticated administrator is susceptible to a Cross-Site Request Forgery (CSRF) attack. This vulnerability, rated Medium (CVSS 6.8), allows an attacker to execute untrusted code on the server, leading to high impact on confidentiality, integrity, and availability. There is no public exploit code, active exploitation, or significant community discussion reported for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.14CPE matchmatch criteria | cpe:2.3:a:pagerduty:rundeck:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.3CPE matchmatch criteria | cpe:2.3:a:pagerduty:rundeck:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.