{"id":"GHSA-4262-wr7p-gpcj","summary":"Rundeck Community Edition vulnerable to Cross-site Scripting","details":"An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp.","aliases":["CVE-2019-6804"],"modified":"2024-02-20T05:22:36.634042Z","published":"2022-05-13T01:06:55Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-22T18:46:01Z","nvd_published_at":"2019-01-25T05:29:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-6804"},{"type":"WEB","url":"https://github.com/rundeck/rundeck/issues/4406"},{"type":"WEB","url":"https://github.com/rundeck/rundeck/commit/e992e94bba22d9fca3a669f0d02c85b80a19f848"},{"type":"WEB","url":"https://docs.rundeck.com/docs/history/version-3.0.13.html"},{"type":"PACKAGE","url":"https://github.com/rundeck/rundeck"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/46251"}],"affected":[{"package":{"name":"org.rundeck:rundeck","ecosystem":"Maven","purl":"pkg:maven/org.rundeck/rundeck"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.13"}]}],"versions":["3.0.0-20180727","3.0.0-alpha1","3.0.1-20180803","3.0.10-20181220","3.0.11-20181221","3.0.12-20190114","3.0.2-20180803","3.0.2-20180817","3.0.5-20180828","3.0.7-20181008","3.0.8-20181029","3.0.9-20181127"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4262-wr7p-gpcj/GHSA-4262-wr7p-gpcj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}