Redhat

Ansible Automation Platform

51 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 18.08.2026 15:51:10
  • Zuletzt bearbeitet 20.08.2026 13:08:53

A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload ...

  • EPSS 0.26%
  • Veröffentlicht 18.08.2026 15:50:54
  • Zuletzt bearbeitet 20.08.2026 13:08:53

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL...

  • EPSS 0.11%
  • Veröffentlicht 13.08.2026 18:17:25
  • Zuletzt bearbeitet 14.08.2026 19:07:46

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS config...

  • EPSS 0.16%
  • Veröffentlicht 27.07.2026 19:17:14
  • Zuletzt bearbeitet 04.08.2026 21:16:34

A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentic...

  • EPSS 0.82%
  • Veröffentlicht 22.07.2026 12:11:29
  • Zuletzt bearbeitet 22.07.2026 19:17:03

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts se...

  • EPSS 0.95%
  • Veröffentlicht 22.07.2026 12:06:36
  • Zuletzt bearbeitet 22.07.2026 16:23:35

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the...

  • EPSS 0.39%
  • Veröffentlicht 22.07.2026 11:15:53
  • Zuletzt bearbeitet 22.07.2026 18:16:59

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_upda...

  • EPSS 0.42%
  • Veröffentlicht 23.06.2026 19:40:33
  • Zuletzt bearbeitet 16.07.2026 12:17:00

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged mess...

  • EPSS 0.89%
  • Veröffentlicht 16.06.2026 14:52:06
  • Zuletzt bearbeitet 29.06.2026 18:16:36

A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. A...

  • EPSS 0.28%
  • Veröffentlicht 15.06.2026 08:36:06
  • Zuletzt bearbeitet 20.08.2026 16:17:23

A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authoriz...