Red Hat Ansible Automation Platform是美国Red Hat公司的一款实现战略性自动化的统一解决方案。 Red Hat Ansible Automation Platform存在授权问题漏洞,该漏洞源于Event-Driven Ansible websocket API缺少授权,端点/api/eda/ws/ansible-rulebook在处理Worker消息时不验证用户权限,任何经过身份验证的用户都可以发送特制消息,获取与激活相关的明文凭证,包括OAuth令牌、vault密
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1781741251< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:1.1.19-1.el8ap< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:1.1.19-1.el9ap< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1781732675< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:1.2.9-2.el9ap< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1781730525< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:1.1.19-1.el8ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:1.1.19-1.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:1.2.9-2.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1781741251 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1781732675 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1781730525 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.7::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12112 | 7.8 HIGH | Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse |
| CVE-2026-10609 | 6.8 MEDIUM | Openshift/cluster-logging-operator: cluster logging operator creates and forwards servicea |
| CVE-2026-11820 | 6.5 MEDIUM | Community.general: community.general nexmo — api credentials exposed in get url query stri |
| CVE-2026-9073 | 6.2 MEDIUM | Foreman-mcp-server: mcp server: insecure sensitive http header sanitization |
| CVE-2026-11819 | 5.5 MEDIUM | Community.general: community.general keyring_info — os keyring passphrase returned in plai |
| CVE-2026-12969 | 5.3 MEDIUM | Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation |
| CVE-2026-55655 | 5.0 MEDIUM | Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat ente |
| CVE-2026-12892 | 4.4 MEDIUM | Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 na |
| CVE-2026-55653 | 4.3 MEDIUM | Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path du |
| CVE-2026-12891 | 4.3 MEDIUM | Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266 |
| CVE-2026-55654 | 3.7 LOW | Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi in |
No comments yet