Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http header
Vulnerability Description
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Vulnerability Type
证书验证不恰当
Vulnerability Title
Red Hat Ansible Automation Platform 加密问题漏洞
Vulnerability Description
Red Hat Ansible Automation Platform是美国Red Hat公司的一款信息化产品。 Red Hat Ansible Automation Platform 2版本存在加密问题漏洞,该漏洞源于aap-gateway组件绕过mTLS认证问题,攻击者可通过操纵事件流URL和伪造HTTP Subject头,利用错误消息中泄露的证书主题信息,向EDA注入任意事件,可能触发自动化工作流。
CVSS Information
N/A
Vulnerability Type
N/A