7.5

CVE-2026-12383

Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn

A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentication without verifying that the header originated from a trusted proxy. Additionally, the expected certificate Distinguished Name is leaked in the 403 error response body. An attacker who can reach the EDA API endpoint with a spoofed Subject header can inject arbitrary events into mTLS-protected event streams, triggering downstream automation actions.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
Produkt Red Hat Ansible Automation Platform 2.5 for RHEL 8
Default Statusaffected
Version 0:1.1.21-1.el8ap
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Ansible Automation Platform 2.5 for RHEL 9
Default Statusaffected
Version 0:1.1.21-1.el9ap
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Ansible Automation Platform 2.6 for RHEL 9
Default Statusaffected
Version 0:1.2.11-1.el9ap
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Ansible Automation Platform 2.7
Default Statusaffected
Version 1785374869
Version < *
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

https://access.redhat.com/security/cve/CVE-2026-12383
https://bugzilla.redhat.com/show_bug.cgi?id=2489127
https://access.redhat.com/errata/RHSA-2026:50340
https://access.redhat.com/errata/RHSA-2026:50319
https://access.redhat.com/errata/RHSA-2026:50336