在 Rundeck 6.2.0 之前的版本中存在一个路径遍历漏洞,允许仅拥有项目配置访问控制列表(ACL)权限的用户,通过将 resources.source.N.config.file 设置为任意绝对路径,来读取服务器上的任意文件。攻击者可以通过 editProjectNodeSourceFile API 或 apiSourceGetContent 端点获取文件内容,从而获取数据库密码、LDAP 绑定凭据以及其他项目的敏感数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet