Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1657

Опубликовано: 25 апр. 2024
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system.

EPSS

Процентиль: 23%
0.00075
Низкий

8.1 High

CVSS3

Дефекты

CWE-1385

Связанные уязвимости

CVSS3: 8.1
redhat
почти 2 года назад

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system.

CVSS3: 8.1
github
почти 2 года назад

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system.

CVSS3: 8.1
fstec
почти 2 года назад

Уязвимость пакетов automation-eda-controller/ansible-rulebook/ansible-automation-platform-installer платформы автоматизации Red Hat Ansible Automation Platform, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 23%
0.00075
Низкий

8.1 High

CVSS3

Дефекты

CWE-1385