vendor:
Rundeck Community Edition
by:
Ishaq Mohammed
6.1
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: Rundeck Community Edition
Affected Version From: Before 3.0.13
Affected Version To: 3.0.13
Patch Exists: YES
Related CWE: CVE-2019-6804
CPE: rundeck
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Java
2019
Rundeck Community Edition before 3.0.13 Multiple Stored XSS
Cross-Site Scripting issues affecting multiple fields in the workflow module under job edit form by injecting javascript code in the Arguments, Invocation String, and File Extension field, the input from these fields are rendered in the Execution Preview which is the sink of this vulnerability.
Mitigation:
The issue is now patched by the vendor in version 3.0.13