| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. When attaching a source inventory to a constructed inventory through
the input_inventories relationship endpoint, the controller verifies only that
the requesting user can read the source inventory, rather than that they hold use
permission on it, unlike instance group attachment on the same access class. An
authenticated user who can administer a constructed inventory and has read-only
visibility of an inventory in another organization -- for example an
organization or system auditor -- can attach that foreign inventory as an input.
On synchronization the controller clones every host and host variable, including
secrets, into the attacker's inventory, and because the attacker administers the
constructed inventory they can run ad hoc commands against the cloned hosts,
resulting in cross-tenant disclosure of inventory data and secrets and code
execution against another tenant's managed hosts. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. When attaching a Galaxy or Automation Hub credential to an
organization through the galaxy_credentials relationship endpoint, the
controller verifies only that the requesting user can read the credential,
rather than that they hold use permission on it, unlike other credential
consumption in the product. An authenticated user who administers one
organization and has read-only visibility of a credential in another
organization -- for example a platform auditor -- can bind that foreign
credential to their own organization. On the next project synchronization the
controller decrypts the credential server-side and uses its token to
authenticate to the credential owner's Automation Hub, allowing cross-tenant use
of another organization's secret. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The GALAXY_TASK_ENV setting, whose values are added to the
environment of the ansible-galaxy commands run during project updates, is not
validated to exclude dynamic-linker and interpreter environment variables such
as LD_PRELOAD and PYTHONPATH, unlike the sibling AWX_TASK_ENV setting. A user
with the system administrator role can set these variables to point at a file
placed inside a project checkout on the shared projects volume, causing
arbitrary native or Python code to execute inside the project synchronization
execution environment on the control plane. This yields read and write access
to every organization's project content and to injected Galaxy server tokens,
resulting in a cross-tenant compromise of the automation content supply chain. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. A project has a signature validation credential foreign key used to
validate signed project content. Unlike the project's SCM credential, the
authorization logic does not verify that the requesting user has use permission
on the referenced credential, and the API field has no validator or type
restriction. An authenticated user holding only the organization project
administrator role can therefore bind an arbitrary credential belonging to
another organization, by its identifier, when creating or updating a project.
The controller discloses that credential's name and type in the project's
summary information and, during project synchronization, decrypts the bound
credential and uses it in the attacker-controlled project's update, allowing a
cross-tenant authorization boundary violation and information disclosure. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. When attaching an instance group to a schedule or a workflow job
template node through the dedicated API relationship endpoint, the controller
verifies only that the requesting user can read (view) the instance group,
rather than that they hold use permission on it, unlike every other instance
group assignment in the product. An authenticated user with read-only
visibility of an instance group -- for example a system auditor -- can attach a
use-restricted instance group, including the control plane group or another
tenant's container group, to a schedule or workflow node they control. Their
playbook then executes on the control plane node or within another tenant's
execution environment, leading to privilege escalation and, in the control
plane case, full compromise of the platform. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-controller.
The host_filter query parameter on the hosts list API is parsed into a raw Django
ORM filter whose lookup path is validated only against a sensitive-field blocklist,
with no authorization check on the database relations it traverses. Because job
event and ad-hoc command output fields are not on that blocklist, an authenticated
user holding only the Read role on an inventory can construct filters that traverse
into the output of jobs they have no permission to view and use the returned host
count as a boolean oracle. Using regular-expression lookups, the attacker can
extract, character by character, the output (which routinely contains plaintext
credentials, tokens, and command results) of jobs and ad-hoc commands belonging to
other organizations, resulting in cross-tenant disclosure of job output |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. Notification template password fields are encrypted with a key
derived from the secret key, the object primary key, and the field name, but not
the subfield name, and the API returns the full ciphertext of a password subfield
after the notification type is changed to one that does not define that subfield.
A user with administrative access to a single notification template, but without
any wider privilege, can switch the template type to reveal the stored
ciphertext, replant that ciphertext into a webhook password field pointing at a
server they control, and trigger a test notification. The controller decrypts the
replayed ciphertext to the original plaintext and sends it to the attacker's
server in an HTTP Basic authorization header, allowing recovery of Slack,
PagerDuty, Twilio, AWS SNS, and Grafana credentials the administrator was only
permitted to use, not read. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The Thycotic Secret Server external credential plugin passes a
user-supplied server URL to its SDK without validating the scheme, host, or IP
range, and the plugin backend is executed synchronously within the automation
controller web process. Using the external credential test endpoint, a user who
holds only the use role on such a credential can override the stored server URL
with an arbitrary internal address, causing the control plane to issue requests
to internal services. Although the response is a generic error, response timing
reveals whether internal hosts and ports are reachable, enabling internal
network reconnaissance and a blind request-forgery primitive from the control
plane, and each request can hold a web worker, affecting availability. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-controller.
When creating or editing an execution environment, the controller does not verify
that the requesting user has use permission on the container registry credential
referenced by the execution environment; it validates only the organization and
the credential kind. An authenticated user who is an execution-environment admin
of one organization can associate a container registry credential belonging to a
different organization -- one they cannot otherwise read, list, or use -- to an
execution environment they control. When a job runs with that execution
environment, the controller decrypts the foreign credential's registry password
and supplies it to the container runtime, disclosing another organization's
registry credentials across the tenant boundary. |
| automation-controller: InventorySource.source_vars lacks
prevent_search, enabling zero-privilege cross-tenant
extraction of inline inventory-plugin credentials via the
credential_types FieldLookupBackend count-oracle |
| xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications. |
| A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0. |
| A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner Interceptor. The manipulation of the argument orders[0].column leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is ea7f0fae7cb0fd998a3284c11addce689350cd69. It is suggested to install a patch to address this issue. |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). |
| Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a maliciously formed field.
This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120 and Archer AX12 v1.0: up to 1.5.1 Build 20260721. |
| A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context. |
| SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged employee to retrieve employee records belonging to other departments and users |