在 Ansible Automation Platform 的 automation-controller 邮件通知后端中发现了一个服务器端请求伪造(SSRF)漏洞。该邮件后端将用户提供的 SMTP 主机和端口(来自通知模板)直接传递给 SMTP 客户端,而未验证目标地址是否为内部地址、回环地址、链路本地地址或保留地址。具有组织“notification-admin”(通知管理员)权限的已认证用户可以创建或修改指向任意内部地址的邮件通知模板,触发测试,并使控制器任务处理程序向该地址发起原始 TCP 连接。由此产生的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | 1789580684 ~ * |
cpe:/a:redhat:ansible_automation_platform:2.7::el9
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84474 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: view_jobtem |
| CVE-2026-84502 | 9.9 CRITICAL | Automation-controller: automation-controller-container: automation-controller: project scm |
| CVE-2026-84719 | 9.9 CRITICAL | Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitiz |
| CVE-2026-75884 | 9.1 CRITICAL | Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in c |
| CVE-2026-96275 | 8.8 HIGH | Flatpak: flatpak: arbitrary write access as root via extra-data extraction |
| CVE-2026-84691 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: format stri |
| CVE-2026-84683 | 8.7 HIGH | Automation-controller: automation-controller-container: automation-controller: stored cros |
| CVE-2026-76648 | 8.5 HIGH | Automation-controller: automation-controller-container: aap controller: copyapiview.post() |
| CVE-2026-84486 | 8.2 HIGH | Automation-controller: automation-controller-container: automation-controller: unauthentic |
| CVE-2026-96512 | 7.8 HIGH | Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authori |
| CVE-2026-96889 | 7.8 HIGH | Librsvg: use-after-free when xml includes have duplicated entities |
| CVE-2026-84499 | 7.7 HIGH | Automation-controller: automation-controller-container: automation-controller: write-only |
| CVE-2026-84706 | 7.6 HIGH | Automation-controller: automation-controller-container: automation-controller: credential |
| CVE-2026-96541 | 7.5 HIGH | Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake d |
| CVE-2026-75887 | 7.5 HIGH | Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handle |
| CVE-2026-88830 | 7.5 HIGH | Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pr |
| CVE-2026-88832 | 7.3 HIGH | Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label |
| CVE-2026-85475 | 7.2 HIGH | Automation-controller: automation-controller-container: automation-controller: rsyslog con |
| CVE-2026-75886 | 7.2 HIGH | Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd |
| CVE-2026-84714 | 7.1 HIGH | Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jin |
Showing top 20 of 46 CVEs. View all on vendor page → →
No comments yet