在 Ansible Automation Platform (AAP) 网关中发现了一个授权绕过漏洞。该网关 API 允许经过身份验证的管理员为 Controller 服务集群创建新的服务密钥。由于服务密钥的创建并未严格限制在安装程序预置的合法路径中,管理员所颁发的密钥在密码学层面与合法密钥无法区分,攻击者可利用其伪造服务身份验证令牌,从而冒充 Controller 服务。 结合网关的 OIDC 工作负载身份端点(通过配置 启用),攻击者能够驱动网关为任意 Controller 工作负载签名工作负载身份令牌(Wor
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90959 | 8.1 HIGH | Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enabl |
| CVE-2026-95521 | 7.8 HIGH | Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when i |
| CVE-2026-95519 | 7.8 HIGH | Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify m |
| CVE-2026-97185 | 7.8 HIGH | Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file |
| CVE-2026-97177 | 6.6 MEDIUM | Keycloak-services: keycloak-services: generic user update bypasses denied reset-password p |
| CVE-2026-97311 | 4.3 MEDIUM | Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups |
| CVE-2026-97176 | 4.2 MEDIUM | Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cook |
No comments yet