CLEANSTART-2026-IY13000

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-IY13000.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-IY13000
Upstream
  • CVE-2026-47893
Published
2026-10-06T00:34:52Z
Modified
2026-10-06T01:00:03Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason
Details

Security vulnerability affects the rundeck package. A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason.

References

Affected packages

CleanStart / rundeck

Package

Name
rundeck

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.1.0-r3

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-IY13000.json"