Redhat

Ansible Automation Platform

81 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 23.09.2026 19:40:11
  • Zuletzt bearbeitet 24.09.2026 15:17:46

A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATO...

  • EPSS 0.43%
  • Veröffentlicht 23.09.2026 19:40:07
  • Zuletzt bearbeitet 25.09.2026 19:17:58

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to c...

  • EPSS 0.29%
  • Veröffentlicht 23.09.2026 19:40:06
  • Zuletzt bearbeitet 24.09.2026 15:17:44

A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first i...

  • EPSS 0.31%
  • Veröffentlicht 23.09.2026 19:39:57
  • Zuletzt bearbeitet 26.09.2026 23:16:37

A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-h...

  • EPSS 0.41%
  • Veröffentlicht 23.09.2026 19:39:52
  • Zuletzt bearbeitet 24.09.2026 16:17:10

A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account toke...

  • EPSS 0.2%
  • Veröffentlicht 23.09.2026 19:02:26
  • Zuletzt bearbeitet 24.09.2026 14:51:56

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user objec...

  • EPSS 0.26%
  • Veröffentlicht 23.09.2026 19:02:18
  • Zuletzt bearbeitet 25.09.2026 18:17:30

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequence...

  • EPSS 0.38%
  • Veröffentlicht 23.09.2026 18:47:54
  • Zuletzt bearbeitet 26.09.2026 23:16:37

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalid...

  • EPSS 0.62%
  • Veröffentlicht 23.09.2026 18:47:26
  • Zuletzt bearbeitet 24.09.2026 06:17:02

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls...

  • EPSS 0.8%
  • Veröffentlicht 23.09.2026 18:41:18
  • Zuletzt bearbeitet 24.09.2026 06:17:01

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API represent...