PagerDuty's vulnerability footprint centers on incident-management and automation platform products that sit within operational technology stacks and DevOps pipelines, where privileged access and event data handling create a sensitive security perimeter. Its disclosures cluster around access-control and credential-handling weaknesses—including missing authorization, authorization bypass, insufficiently protected credentials, and cross-site request forgery—that are characteristic of web-based platforms integrating with external services and managing sensitive operational context. The vendor's vulnerabilities skew toward moderate severity outcomes and demonstrate a moderate tendency toward public exploit availability; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pagerduty over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-6804MEDIUM An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.g | Jan 25, 2019 | 6.1 | 33 | NO | YES |
CVE-2022-29186CRITICAL Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated S | May 20, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-39132HIGH Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, an authorized user can upload a zip-for | Aug 30, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-3800HIGH CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local | Aug 5, 2019 | 7.8 | 26 | NO | NO |
CVE-2022-31044HIGH Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4. | Jun 15, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-41112HIGH Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or | Feb 28, 2022 | 8.1 | 25 | NO | NO |
CVE-2025-52493MEDIUM PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actu | Dec 10, 2025 | 6.5 | 23 | NO | NO |
CVE-2021-39133MEDIUM Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, a user with `admin` access to the `syst | Aug 30, 2021 | 6.8 | 23 | NO | NO |
CVE-2021-41111MEDIUM Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to re | Feb 28, 2022 | 5.4 | 20 | NO | NO |
CVE-2023-48222MEDIUM Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in both Rundeck Open Source and Proce | Nov 16, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pagerduty.
Media articles that mention a CVE ID that affects a product developed by Pagerduty — matched by CVE ID, not by vendor name.