在 foreman_ansible 插件的 Ansible 覆盖值 API 中发现了一个漏洞。该 API 的 destroy(删除)操作通过 ID 解析目标 LookupValue 记录时,未验证该记录是否属于调用者有权限编辑的 AnsibleVariable。拥有 edit_ansible_variables 权限的已认证用户可通过 ID 删除任意 LookupValue 记录,包括位于其权限过滤范围之外的 Ansible 变量的覆盖值,以及属于 Puppet 智能类参数(Puppet smart class p
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86320 | 7.8 HIGH | Flatpak-builder: host code execution via `git am` hook execution in patch source extractio |
| CVE-2026-92904 | 4.3 MEDIUM | Rubygem-foreman_remote_execution: job output readable without object-level view_job_invoca |
| CVE-2026-92893 | 4.3 MEDIUM | Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, expo |
No comments yet