Galaxy NG是美国Ansible公司开源的新一代后端服务。 Ansible Galaxy NG存在命令注入漏洞,该漏洞源于galaxy_ng中do_git_checkout()函数将未经过清理的git ref名称插入shell命令,可能导致经过身份验证的用户通过创建包含shell元字符的分支或标签实现在pulp worker上远程执行代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | any |
unaffected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
unknown | ||
any |
unknown | ||
any |
unknown | ||
| … +1 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10649 | 8.6 HIGH | Pacemaker: pacemaker: denial of service via integer overflow in remote message decompressi |
| CVE-2026-1767 | 5.6 MEDIUM | Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leading |
| CVE-2026-1766 | 5.6 MEDIUM | Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and inform |
| CVE-2026-1765 | 5.6 MEDIUM | Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and potent |
| CVE-2026-1764 | 5.6 MEDIUM | Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leads t |
| CVE-2026-4367 | 5.5 MEDIUM | Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing |
No comments yet