Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-68562

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.

Отчет

This Moderate severity flaw in ansible-collection-redhat-leapp allows an attacker with privileged write access on a managed node to tamper with Leapp report content. When an operator subsequently runs the leapp_corrupted_grubenv_file remediation, the Ansible controller may be tricked into disclosing sensitive controller-local files to the compromised managed node, crossing a trust boundary. Exploitation depends on both prior compromise of the managed node and specific operator action.

Меры по смягчению последствий

To mitigate this issue, avoid running the leapp_corrupted_grubenv_file remediation against managed nodes whose Leapp report content is not trusted. As a local hardening measure, modify the relevant Ansible playbook to explicitly set remote_src: true for ansible.builtin.copy tasks within the leapp_corrupted_grubenv_file role. Additionally, implement path validation to ensure that src paths are strictly confined to the expected /boot subtree. These changes require re-execution of the Ansible playbook to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10ansible-collection-redhat-leappAffected
Red Hat Enterprise Linux 9ansible-collection-redhat-leappAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-610
https://bugzilla.redhat.com/show_bug.cgi?id=2466035ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: Information disclosure via Leapp report tampering

EPSS

Процентиль: 13%
0.00219
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
nvd
6 дней назад

A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.

CVSS3: 6.2
github
6 дней назад

A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.

EPSS

Процентиль: 13%
0.00219
Низкий

6.2 Medium

CVSS3