Описание
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.
Отчет
This Moderate severity flaw in ansible-collection-redhat-leapp allows an attacker with privileged write access on a managed node to tamper with Leapp report content. When an operator subsequently runs the leapp_corrupted_grubenv_file remediation, the Ansible controller may be tricked into disclosing sensitive controller-local files to the compromised managed node, crossing a trust boundary. Exploitation depends on both prior compromise of the managed node and specific operator action.
Меры по смягчению последствий
To mitigate this issue, avoid running the leapp_corrupted_grubenv_file remediation against managed nodes whose Leapp report content is not trusted. As a local hardening measure, modify the relevant Ansible playbook to explicitly set remote_src: true for ansible.builtin.copy tasks within the leapp_corrupted_grubenv_file role. Additionally, implement path validation to ensure that src paths are strictly confined to the expected /boot subtree. These changes require re-execution of the Ansible playbook to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | ansible-collection-redhat-leapp | Affected | ||
| Red Hat Enterprise Linux 9 | ansible-collection-redhat-leapp | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.2 Medium
CVSS3
Связанные уязвимости
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.
EPSS
6.2 Medium
CVSS3