在 Ansible Automation Platform 的 automation-controller 中发现了一个漏洞。该漏洞源于自定义“凭证类型(Credential Type)”的环境变量注入器在验证变量名时,仅依赖一个黑名单机制(包括以 为前缀的检查以及一个固定的 列表),但该黑名单遗漏了可用于进程劫持的加载器变量,例如 、 、 、 、 和 。 结合凭证文件注入功能,攻击者可以诱导特权用户将恶意脚本写入执行环境,并通过设置 变量指向该脚本,从而在对任意附加该类型凭证的作业执行过程中,在“执行环境容器(e
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:4.6.33-1.el8ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:4.6.33-1.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:4.7.17-1.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el10
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1789673739 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1789580684 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.7::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84474 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: view_jobtem |
| CVE-2026-84502 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: project scm |
| CVE-2026-84719 | 9.9 CRITICAL | Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitiz |
| CVE-2026-75884 | 9.1 CRITICAL | Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in c |
| CVE-2026-96275 | 8.8 HIGH | Flatpak: flatpak: arbitrary write access as root via extra-data extraction |
| CVE-2026-84691 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: format stri |
| CVE-2026-84683 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: stored cros |
| CVE-2026-76648 | 8.5 HIGH | Automation-controller: automation-controller-container: aap controller: copyapiview.post() |
| CVE-2026-84486 | 8.2 HIGH | Automation-controller: automation-controller-container: automation-controller: unauthentic |
| CVE-2026-96512 | 7.8 HIGH | Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori |
| CVE-2026-96889 | 7.8 HIGH | Librsvg: use-after-free when xml includes have duplicated entities |
| CVE-2026-84499 | 7.7 HIGH | Automation-controller: automation-controller-container: automation-controller: write-only |
| CVE-2026-96541 | 7.5 HIGH | Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d |
| CVE-2026-75887 | 7.5 HIGH | Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handle |
| CVE-2026-88830 | 7.5 HIGH | Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr |
| CVE-2026-88832 | 7.3 HIGH | Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label |
| CVE-2026-85475 | 7.2 HIGH | Automation-controller: automation-controller-container: automation-controller: rsyslog con |
| CVE-2026-75886 | 7.2 HIGH | Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd |
| CVE-2026-84714 | 7.1 HIGH | Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jin |
| CVE-2026-96445 | 6.8 MEDIUM | Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against |
Showing top 20 of 46 CVEs. View all on vendor page → →
No comments yet