在 Ansible Automation Platform 的 automation-controller 中发现了一个漏洞。在随产品发布的生产配置中,Controller 未经验证是否来自受信任的反向代理,便直接信任客户端提供的 X-Forwarded-For 标量作为请求的客户端 IP 地址,并选择最左侧(由攻击者可控)的标量值。因此,攻击者可以伪造其请求在 Controller 审计日志和访问日志中记录的源 IP 地址,从而降低取证分析和安全信息与事件管理(SIEM)系统中归因的完整性。该漏洞不会赋予攻击者额
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 0:4.6.33-1.el8ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:4.6.33-1.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.5::el8
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:4.7.17-1.el9ap ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el10
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1789673739 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.6::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1789580684 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.7::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84474 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: view_jobtem |
| CVE-2026-84502 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: project scm |
| CVE-2026-84719 | 9.9 CRITICAL | Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitiz |
| CVE-2026-75884 | 9.1 CRITICAL | Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in c |
| CVE-2026-96275 | 8.8 HIGH | Flatpak: flatpak: arbitrary write access as root via extra-data extraction |
| CVE-2026-84691 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: format stri |
| CVE-2026-84683 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: stored cros |
| CVE-2026-76648 | 8.5 HIGH | Automation-controller: automation-controller-container: aap controller: copyapiview.post() |
| CVE-2026-84486 | 8.2 HIGH | Automation-controller: automation-controller-container: automation-controller: unauthentic |
| CVE-2026-96512 | 7.8 HIGH | Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori |
| CVE-2026-96889 | 7.8 HIGH | Librsvg: use-after-free when xml includes have duplicated entities |
| CVE-2026-84499 | 7.7 HIGH | Automation-controller: automation-controller-container: automation-controller: write-only |
| CVE-2026-84706 | 7.6 HIGH | Automation-controller: automation-controller-container: automation-controller: credential |
| CVE-2026-96541 | 7.5 HIGH | Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d |
| CVE-2026-75887 | 7.5 HIGH | Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handle |
| CVE-2026-88830 | 7.5 HIGH | Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr |
| CVE-2026-88832 | 7.3 HIGH | Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label |
| CVE-2026-85475 | 7.2 HIGH | Automation-controller: automation-controller-container: automation-controller: rsyslog con |
| CVE-2026-75886 | 7.2 HIGH | Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd |
| CVE-2026-84714 | 7.1 HIGH | Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jin |
Showing top 20 of 46 CVEs. View all on vendor page → →
No comments yet