Redhat

Ansible Automation Platform

81 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 07.10.2026 05:46:15
  • Zuletzt bearbeitet 07.10.2026 19:17:31

A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, a...

  • EPSS 0.24%
  • Veröffentlicht 06.10.2026 18:18:06
  • Zuletzt bearbeitet 07.10.2026 12:17:08

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query paramete...

  • EPSS 0.45%
  • Veröffentlicht 24.09.2026 12:25:11
  • Zuletzt bearbeitet 24.09.2026 16:17:26

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted t...

  • EPSS 0.29%
  • Veröffentlicht 23.09.2026 19:40:42
  • Zuletzt bearbeitet 26.09.2026 23:16:38

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewher...

  • EPSS 0.27%
  • Veröffentlicht 23.09.2026 19:40:36
  • Zuletzt bearbeitet 24.09.2026 15:17:45

A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in prevent_search() a...

  • EPSS 0.14%
  • Veröffentlicht 23.09.2026 19:40:33
  • Zuletzt bearbeitet 24.09.2026 15:17:45

A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from ...

  • EPSS 0.34%
  • Veröffentlicht 23.09.2026 19:40:32
  • Zuletzt bearbeitet 26.09.2026 23:16:37

A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, ca...

  • EPSS 0.18%
  • Veröffentlicht 23.09.2026 19:40:28
  • Zuletzt bearbeitet 24.09.2026 16:17:12

A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 certific...

  • EPSS 0.31%
  • Veröffentlicht 23.09.2026 19:40:26
  • Zuletzt bearbeitet 25.09.2026 18:17:31

A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is copied in cl...

  • EPSS 0.34%
  • Veröffentlicht 23.09.2026 19:40:22
  • Zuletzt bearbeitet 24.09.2026 21:00:46

A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonym...