CyberSectr
Menü
← CVE Veritabanı

CVE-2026-84474

Kritik

Teknik Veri (Otomatik)

CVSS Skoru
9.9
EPSS
CWE
CWE-807
KEV Durumu
Hayır

Red Hat Ansible Automation Platform'in automation-controller bileşeninde bir zayıflık bulundu. Provisioning-callback gizli anahtarı (host_config_key) yalnızca read-level view_jobtemplate izni olan kullanıcılar tarafından erişilebiliyor - hem job template API temsilinde hem de etkinlik akışında - ve provisioning callback endpoint, controller AAP gateway arkasında boş bir proxy izin listesiyle dağıtıldığında, istemci tarafından sağlanan X-Forwarded-For başlığını çağırılan hostu belirlemek için güveniyor. Gizli anahtarı okuyan ve X-Forwarded-For'u job template'in envanterindeki herhangi bir host ile eşleştirebilen asgari ayrıcalıklı veya kimliği doğrulanmamış uzaktan bir saldırgan, job template'in kimlik bilgilerini kullanarak job template'i keyfi yönetilen hostlara karşı çalıştırabilir, bu da yönetilen hostlarda ayrıcalık yükselmesine ve uzaktan kod çalıştırılmasına neden olur.

Orijinal açıklama (İngilizce)

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback endpoint trusts a client-supplied X-Forwarded-For header to determine the calling host when the controller is deployed behind the AAP gateway with an empty proxy allow-list. By reading the secret and spoofing X-Forwarded-For to match any host in the job template's inventory, a minimally privileged or unauthenticated remote attacker can launch the job template against arbitrary managed hosts using the job template's credentials, resulting in privilege escalation and remote code execution on managed hosts.

Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.