Описание
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
Меры по смягчению последствий
Currently, there is no mitigation available for this vulnerability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/gateway-rhel8-operator | Under investigation | ||
Red Hat Ansible Automation Platform 2 | automation-eda-controller | Under investigation | ||
Red Hat Ansible Automation Platform 2 | automation-hub | Under investigation |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-497
https://bugzilla.redhat.com/show_bug.cgi?id=2379359aap: aap-gateway: automation-hub: Sensitive Information Disclosure
3.5 Low
CVSS3
Связанные уязвимости
CVSS3: 3.5
nvd
27 дней назад
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
CVSS3: 3.5
github
26 дней назад
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
3.5 Low
CVSS3