在 ansible-runner 中发现了一个漏洞。 函数负责接收并解压通过 ansible-runner transmit/worker 协议在 worker 端传输的流式 zip 归档文件。该函数在从归档内容中重建符号链接时,未对链接目标进行验证;同时,它对源自归档成员名称的未经净化的文件系统路径执行了 和 操作。如果 worker 处理了一个由攻击者影响输入所构造的恶意归档,则可能在预期目标目录之外创建文件、创建符号链接或修改权限,进而可能被利用以实现代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96577 | 7.1 HIGH | Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without a |
| CVE-2026-83589 | 6.1 MEDIUM | Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect |
| CVE-2026-103641 | 5.5 MEDIUM | Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder |
No comments yet