| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A flaw was found in Red Hat Ansible Automation Platform's automation-controller.
The host_filter query parameter on the hosts list API is parsed into a raw Django
ORM filter whose lookup path is validated only against a sensitive-field blocklist,
with no authorization check on the database relations it traverses. Because job
event and ad-hoc command output fields are not on that blocklist, an authenticated
user holding only the Read role on an inventory can construct filters that traverse
into the output of jobs they have no permission to view and use the returned host
count as a boolean oracle. Using regular-expression lookups, the attacker can
extract, character by character, the output (which routinely contains plaintext
credentials, tokens, and command results) of jobs and ad-hoc commands belonging to
other organizations, resulting in cross-tenant disclosure of job output |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. Notification template password fields are encrypted with a key
derived from the secret key, the object primary key, and the field name, but not
the subfield name, and the API returns the full ciphertext of a password subfield
after the notification type is changed to one that does not define that subfield.
A user with administrative access to a single notification template, but without
any wider privilege, can switch the template type to reveal the stored
ciphertext, replant that ciphertext into a webhook password field pointing at a
server they control, and trigger a test notification. The controller decrypts the
replayed ciphertext to the original plaintext and sends it to the attacker's
server in an HTTP Basic authorization header, allowing recovery of Slack,
PagerDuty, Twilio, AWS SNS, and Grafana credentials the administrator was only
permitted to use, not read. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-controller. The
Project SCM branch and SCM refspec fields are accepted without rejecting values that begin
with a dash and are passed to the git module during project synchronization, where they
reach a `git checkout`/`git fetch` command line as bare arguments with no end-of-options
separator. An authenticated user permitted to create or edit a project can set the SCM
branch to a git option such as `--pathspec-from-file=<path>`, causing git to read an
arbitrary file on the synchronization host and reflect its contents back through the
project-update output. Because project synchronization runs on the control-plane host on
default OpenShift Operator deployments, an attacker can read the control-plane Kubernetes
ServiceAccount token, the Controller SECRET_KEY, and the database credentials, leading to
full compromise of the Automation Platform and its Kubernetes namespace. System
administrator privileges are not required and the impact crosses tenants. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The Thycotic Secret Server external credential plugin passes a
user-supplied server URL to its SDK without validating the scheme, host, or IP
range, and the plugin backend is executed synchronously within the automation
controller web process. Using the external credential test endpoint, a user who
holds only the use role on such a credential can override the stored server URL
with an arbitrary internal address, causing the control plane to issue requests
to internal services. Although the response is a generic error, response timing
reveals whether internal hosts and ports are reachable, enabling internal
network reconnaissance and a blind request-forgery primitive from the control
plane, and each request can hold a web worker, affecting availability. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. When attaching an instance group to a schedule or a workflow job
template node through the dedicated API relationship endpoint, the controller
verifies only that the requesting user can read (view) the instance group,
rather than that they hold use permission on it, unlike every other instance
group assignment in the product. An authenticated user with read-only
visibility of an instance group -- for example a system auditor -- can attach a
use-restricted instance group, including the control plane group or another
tenant's container group, to a schedule or workflow node they control. Their
playbook then executes on the control plane node or within another tenant's
execution environment, leading to privilege escalation and, in the control
plane case, full compromise of the platform. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-controller. When a
custom credential type is created or updated, the injector configuration is validated by
rendering each attacker-supplied Jinja2 template synchronously inside the web request
worker, with no limit on iteration count, output size, or execution time. An
authenticated superuser can submit a credential type whose injector contains deeply
nested loops or large string operations, consuming CPU and wall-clock time in the web
worker until it is killed by the request timeout; issuing enough concurrent requests
places all web workers into a kill-and-respawn loop, making the Controller API and UI
unavailable for the duration of the attack. Additionally, certain template constructs
raise exception types that the validator does not handle, resulting in an unhandled
server error (HTTP 500) instead of a clean validation error. The rendering sandbox
prevents code execution, so there is no confidentiality or integrity impact. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. When attaching a Galaxy or Automation Hub credential to an
organization through the galaxy_credentials relationship endpoint, the
controller verifies only that the requesting user can read the credential,
rather than that they hold use permission on it, unlike other credential
consumption in the product. An authenticated user who administers one
organization and has read-only visibility of a credential in another
organization -- for example a platform auditor -- can bind that foreign
credential to their own organization. On the next project synchronization the
controller decrypts the credential server-side and uses its token to
authenticate to the credential owner's Automation Hub, allowing cross-tenant use
of another organization's secret. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. When attaching a source inventory to a constructed inventory through
the input_inventories relationship endpoint, the controller verifies only that
the requesting user can read the source inventory, rather than that they hold use
permission on it, unlike instance group attachment on the same access class. An
authenticated user who can administer a constructed inventory and has read-only
visibility of an inventory in another organization -- for example an
organization or system auditor -- can attach that foreign inventory as an input.
On synchronization the controller clones every host and host variable, including
secrets, into the attacker's inventory, and because the attacker administers the
constructed inventory they can run ad hoc commands against the cloned hosts,
resulting in cross-tenant disclosure of inventory data and secrets and code
execution against another tenant's managed hosts. |
| xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications. |
| A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0. |
| A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner Interceptor. The manipulation of the argument orders[0].column leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is ea7f0fae7cb0fd998a3284c11addce689350cd69. It is suggested to install a patch to address this issue. |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). |
| Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a maliciously formed field.
This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120 and Archer AX12 v1.0: up to 1.5.1 Build 20260721. |
| A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context. |
| SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged employee to retrieve employee records belonging to other departments and users |
| A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations. |
| Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service. |