Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8mm-5386-h387

Опубликовано: 25 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system.

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system.

EPSS

Процентиль: 31%
0.00378
Низкий

8.1 High

CVSS3

Дефекты

CWE-1385
CWE-319

Связанные уязвимости

CVSS3: 8.1
redhat
больше 2 лет назад

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system.

CVSS3: 8.1
nvd
больше 2 лет назад

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system.

CVSS3: 8.1
fstec
больше 2 лет назад

Уязвимость пакетов automation-eda-controller/ansible-rulebook/ansible-automation-platform-installer платформы автоматизации Red Hat Ansible Automation Platform, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 31%
0.00378
Низкий

8.1 High

CVSS3

Дефекты

CWE-1385
CWE-319