Red Hat Ansible Automation Platform是美国Red Hat公司的一款信息化产品。 Red Hat Ansible Automation Platform存在授权问题漏洞,该漏洞源于AAP Gateway Envoy代理配置问题,非mTLS路由到EDA事件流未移除来自客户端请求的Subject HTTP标头,可能导致未经身份验证的远程攻击者注入伪造的Subject标头,绕过mTLS身份验证并向受保护的EDA事件流注入任意事件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:2.5.20260715-1.el8ap< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:2.5.20260715-1.el9ap< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1777311120< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:2.6.20260422-1.el9ap< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1783919486< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:2.5.20260715-1.el8ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:2.5.20260715-1.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:2.6.20260422-1.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el10
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1777311120 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1783919486 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.7::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15809 | 7.8 HIGH | Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env |
| CVE-2026-14251 | 7.7 HIGH | Gitops-operator: gitops-operator: missing allowednamespace check in reconcilerhook for clu |
| CVE-2026-15779 | 6.1 MEDIUM | Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validatio |
No comments yet