Vulnerabilities
Products Security index
Vulnerabilities
CVE-2025-52493
PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "password" to "text" using browser developer tools. This vulnerability is exploitable by administrative users who have access to the configuration page.
CVE-2023-47112
Authenticated users can view job names and groups they do not have authorization to view in Rundeck
CVE-2023-48222
Authenticated users can view or delete jobs they do not have authorization for in Rundeck
CVE-2022-31044
Plaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process Automation
CVE-2022-29186
Use of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterprise
