Security: Normation/rudder
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Bypass of node policy download ACLGHSA-x92w-5577-fr2c published
Jan 24, 2026 by amoussetHigh -
Credential leakage via XXE in archive import APIGHSA-95jf-pgjx-pxp5 published
Aug 25, 2025 by amoussetHigh -
Bypass of tenant restrictions for API tokensGHSA-2c48-mj92-9c3c published
Aug 25, 2025 by amoussetLow -
Lack of proper ACL for event log rollback endpointGHSA-m65p-9wx2-8fr7 published
Aug 25, 2025 by amoussetModerate -
Path traversal in Technique Creation APIGHSA-6v2g-f264-5c4r published
Aug 25, 2025 by amoussetLow -
XSS via score details of nodesGHSA-xvxj-ffqq-7qm3 published
Aug 25, 2025 by amoussetLow -
RCE via ZipSlip vulnerability in archive import APIGHSA-p3mv-j8j4-xqh7 published
Aug 25, 2025 by amoussetModerate -
RCE via inventory upload and debug script endpointGHSA-xh8f-cw8w-j27g published
Aug 25, 2025 by amoussetModerate -
Built-in roles and userAccount_write permission allow ATO and privilege escalationGHSA-246r-fjcq-548w published
Aug 25, 2025 by amoussetHigh -
Path traversal in resource files APIGHSA-h66x-c5pj-f5f8 published
Apr 24, 2025 by amoussetLow