Red Hat Ansible Automation Platform(Red Hat AAP)是美国红帽(Red Hat)公司的一款实现战略性自动化的统一解决方案。 Red Hat Ansible Automation Platform(Red Hat AAP)存在安全漏洞,该漏洞源于构建过程中/etc/passwd文件被设置为组可写权限,可能导致攻击者在容器内获得完整root权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
unaffected | ||
any |
affected | ||
| Red Hat | Red Hat Ansible Automation Platform 2.16 | 1789001438< * |
unaffected |
1789023765< * |
unaffected | ||
| Red Hat | Red Hat Ansible Automation Platform 2.18 | 1789023329< * |
unaffected |
1789001715< * |
unaffected | ||
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1784035663< * |
unaffected |
1789634812< * |
unaffected | ||
1784051694< * |
unaffected | ||
1789654540< * |
unaffected | ||
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1789658734< * |
unaffected |
1789661423< * |
unaffected | ||
1789654312< * |
unaffected | ||
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1788901236< * |
unaffected |
1789582543< * |
unaffected | ||
1789584820< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.16 | 1789001438 ~ * |
cpe:/a:redhat:ansible_core:2.16::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.16 | 1789023765 ~ * |
cpe:/a:redhat:ansible_core:2.16::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.18 | 1789023329 ~ * |
cpe:/a:redhat:ansible_core:2.18::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.18 | 1789001715 ~ * |
cpe:/a:redhat:ansible_core:2.18::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1784035663 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1789634812 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1784051694 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1789654540 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1789658734 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1789661423 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1789654312 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1788901236 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.7::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1789582543 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.7::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1789584820 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.7::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32589 | 7.4 HIGH | Mirror-registry: quay: insecure direct object reference in blobupload |
| CVE-2026-32590 | 7.1 HIGH | Mirror-registry: remote code execution using pickle deserialization |
| CVE-2026-2377 | 6.5 MEDIUM | Mirror-registry: quay: quay: server-side request forgery via log export functionality |
| CVE-2025-57851 | 6.4 MEDIUM | Mce: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-57854 | 6.4 MEDIUM | Osus-operator: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-57853 | 6.4 MEDIUM | Web-terminal: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-58713 | 6.4 MEDIUM | Rhpam: privilege escalation via excessive /etc/passwd permissions |
| CVE-2025-14243 | 5.3 MEDIUM | Mirror-registry: openshift mirror registry: user enumeration via authentication error mess |
| CVE-2026-32591 | 5.2 MEDIUM | Mirror-registry: quay: server-side request forgery in proxy cache upstream registry config |
No comments yet