Impact
An authenticated user with authorization to read webhooks in one project, can craft a request to reveal Webhook definitions and tokens in another project. The user could use the revealed webhook tokens to trigger webhooks.
Severity depends on trust level of authenticated users, and whether any webhooks exist that trigger sensitive actions.
Patches
Patched in release 3.4.5, 3.3.15
Workarounds
None
References
Release Notes: 3.4.5
For more information
If you have any questions or comments about this advisory:
To report security issues to Rundeck please use the form at http://rundeck.com/security
Impact
An authenticated user with authorization to read webhooks in one project, can craft a request to reveal Webhook definitions and tokens in another project. The user could use the revealed webhook tokens to trigger webhooks.
Severity depends on trust level of authenticated users, and whether any webhooks exist that trigger sensitive actions.
Patches
Patched in release 3.4.5, 3.3.15
Workarounds
None
References
Release Notes: 3.4.5
For more information
If you have any questions or comments about this advisory:
To report security issues to Rundeck please use the form at http://rundeck.com/security