CVE-2026-84502
KritikTeknik Veri (Otomatik)
- CVSS Skoru
- 9.9
- EPSS
- —
- CWE
- CWE-88
- KEV Durumu
- Hayır
Red Hat Ansible Automation Platform'in automation-controller bileşeninde bir zayıflık bulundu. Proje scm_url alanı, tire ile başlayan değerlere karşı doğrulanmıyor ve git SCM modülüne olduğu gibi depolanıyor ve iletiliyor. Modül, URL'yi konum argümanı olarak "--" ayırıcısı olmadan git ls-remote ile çalıştırdığı için, "--upload-pack=<komut>:x" gibi bir git proje URL'si, git tarafından --upload-pack seçeneği olarak yorumlanıyor ve bir kabuk aracılığıyla yürütülüyor. Tek bir organizasyonda proje oluşturma veya değiştirme izni olan bir kullanıcı, bu şekilde kontrol düzlemi görev podunda keyfi komutları çalıştırabilir ve çıktı, proje güncelleme stdout uç noktası aracılığıyla yansıtılarak, çoklu kiracılı uzlaşma ve küme içi lateral hareket meydana gelebilir.
Orijinal açıklama (İngilizce)
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--" separator, a git project URL such as "--upload-pack=<command>:x" is interpreted by git as the --upload-pack option and executed via a shell. A user with permission to create or modify a project in a single organization can thereby execute arbitrary commands on the control-plane task pod, with output reflected through the project update stdout endpoint, leading to cross-tenant compromise and in-cluster lateral movement
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
