在事件驱动 Ansible(EDA)服务器中发现了一个漏洞。ExternalEventStreamViewSet 使用了宽松的访问控制策略(permission_classes=[AllowAny],authentication_classes=[]),仅依赖 Subject HTTP 头的值进行 mTLS 认证,而未验证该头是否来自受信任的代理。此外,预期的证书“ distinguished name”(可区分名称)会在 403 错误响应体中泄露。攻击者若能通过伪造 Subject 头访问 EDA API 端点,
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:1.1.21-1.el8ap< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:1.1.21-1.el9ap< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:1.2.11-1.el9ap< * |
unaffected |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1785374869< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:1.1.21-1.el8ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:1.1.21-1.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:1.2.11-1.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el10
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1785374869 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.7::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17527 | 7.7 HIGH | Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrol |
| CVE-2026-15003 | 5.6 MEDIUM | Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and |
No comments yet