Ansible 平台 UI 中存在一个基于 DOM 的跨站脚本(XSS)漏洞,该漏洞源于应用程序在重定向路由中对输入缺乏有效验证。具体而言,应用程序从 查询参数中提取目标地址,并直接将其赋值给浏览器的 ,而未验证其格式或协议方案(scheme)。尽管该平台上集成了内置的 URL 验证功能,旨在阻止恶意 URI 方案(如 和 )以及指向外部站点或协议相关的重定向,但此特定重定向路由绕过了这些安全控制措施。因此,攻击者可构造恶意链接,当认证用户访问该链接时,将在该用户会话上下文中执行任意 JavaScript 代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Hardened Images | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106062 | 7.8 HIGH | Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface file |
| CVE-2026-101258 | 7.8 HIGH | Ghostscript: ghostscript: -dsafer sandbox bypass via type 5 shading oob write and procedur |
| CVE-2026-83550 | 7.1 HIGH | Postgres-exporter: net/http/pprof exposed on metrics listener |
| CVE-2026-104048 | 6.8 MEDIUM | Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation |
| CVE-2026-92821 | 6.8 MEDIUM | Sssd: sssd: access control bypass via premature ldap access rule evaluation |
| CVE-2026-106063 | 6.3 MEDIUM | Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions |
| CVE-2026-104046 | 6.2 MEDIUM | Sssd: sssd: denial of service via incomplete identity provider authentication requests |
| CVE-2026-104044 | 6.2 MEDIUM | Sssd: sssd: denial of service via crafted passkey kerberos authentication request |
| CVE-2026-104038 | 5.9 MEDIUM | Sssd: sssd: denial of service via missing sid extension in certificate mapping |
| CVE-2026-104036 | 5.8 MEDIUM | Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin |
| CVE-2026-104031 | 5.5 MEDIUM | Sssd: sssd: denial of service via memory exhaustion in autofs responder |
| CVE-2026-104032 | 5.5 MEDIUM | Sssd: sssd: denial of service via unprivileged autofs cache invalidation |
| CVE-2026-104035 | 5.5 MEDIUM | Sssd: sssd: denial of service via memory exhaustion in kcm responder |
| CVE-2026-104037 | 5.5 MEDIUM | Sssd: sssd: denial of service via packet length underflow in autofs responder |
| CVE-2026-104041 | 5.5 MEDIUM | Sssd: sssd: denial of service via unbounded negative cache growth |
| CVE-2026-104042 | 5.5 MEDIUM | Sssd: sssd: denial of service via out-of-bounds read in pam responder |
| CVE-2026-104043 | 5.5 MEDIUM | Sssd: sssd: denial of service via undersized packet parsing in nss responder |
| CVE-2026-105305 | 5.4 MEDIUM | Keycloak-services: keycloak-services: device authorization grant bypasses per-client minim |
| CVE-2026-104033 | 5.4 MEDIUM | Sssd: sssd: access control bypass via improper ldap shadow expiration check |
| CVE-2026-104047 | 5.3 MEDIUM | Sssd: sssd: information disclosure via query injection in entra id lookups |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet