在 AAP Controller 的 HashiCorp Vault 凭证插件中发现了一个安全漏洞。awx_plugins/credentials/hashivault.py 文件中的 kubernetes_auth() 函数会读取控制器 Pod 的 Kubernetes 服务账户令牌,并在测试使用 kubernetes_role 认证的 HashiCorp Vault 密钥查找凭证时,将该令牌发送至攻击者控制的 URL。拥有凭证创建权限的经过身份验证的攻击者可借此窃取下述令牌,从而获得对控制平面命名空间的 Kub
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | any |
affected |
any |
affected | ||
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66780 | 9.9 CRITICAL | Submariner-operator: submariner-operator: flat broker trust model grants every spoke full |
| CVE-2026-18963 | 9.1 CRITICAL | Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentia |
| CVE-2026-66793 | 8.8 HIGH | Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary containe |
| CVE-2026-75924 | 8.7 HIGH | Managed-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants clust |
| CVE-2026-66783 | 8.2 HIGH | Submariner-operator: submariner-operator: arbitrary image override enables privileged code |
| CVE-2026-66782 | 7.8 HIGH | Submariner-operator: submariner-operator: broker api bearer token stored cleartext in cr s |
| CVE-2026-71365 | 7.7 HIGH | Awx: webhook status callback ssrf leaks the git pat |
| CVE-2026-15571 | 7.3 HIGH | Keycloak-services: keycloak-services: predictable account-linking hash enables account tak |
| CVE-2026-66781 | 6.5 MEDIUM | Submariner-operator: submariner-operator: ipsec psk stored cleartext in submariner cr spec |
| CVE-2026-75032 | 6.3 MEDIUM | Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder |
| CVE-2026-75485 | 5.5 MEDIUM | Must-gather: must-gather: cluster proxy object dumped raw, bypassing inspect redaction of |
| CVE-2026-73834 | 5.5 MEDIUM | Must-gather: must-gather: embedded secret data in acm wrapper crs collected without redact |
| CVE-2026-19608 | 5.3 MEDIUM | Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy |
No comments yet