| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. Notification template password fields are encrypted with a key
derived from the secret key, the object primary key, and the field name, but not
the subfield name, and the API returns the full ciphertext of a password subfield
after the notification type is changed to one that does not define that subfield.
A user with administrative access to a single notification template, but without
any wider privilege, can switch the template type to reveal the stored
ciphertext, replant that ciphertext into a webhook password field pointing at a
server they control, and trigger a test notification. The controller decrypts the
replayed ciphertext to the original plaintext and sends it to the attacker's
server in an HTTP Basic authorization header, allowing recovery of Slack,
PagerDuty, Twilio, AWS SNS, and Grafana credentials the administrator was only
permitted to use, not read. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The GALAXY_TASK_ENV setting, whose values are added to the
environment of the ansible-galaxy commands run during project updates, is not
validated to exclude dynamic-linker and interpreter environment variables such
as LD_PRELOAD and PYTHONPATH, unlike the sibling AWX_TASK_ENV setting. A user
with the system administrator role can set these variables to point at a file
placed inside a project checkout on the shared projects volume, causing
arbitrary native or Python code to execute inside the project synchronization
execution environment on the control plane. This yields read and write access
to every organization's project content and to injected Galaxy server tokens,
resulting in a cross-tenant compromise of the automation content supply chain. |
| automation-controller: InventorySource.source_vars lacks
prevent_search, enabling zero-privilege cross-tenant
extraction of inline inventory-plugin credentials via the
credential_types FieldLookupBackend count-oracle |
| A flaw was found in Red Hat Ansible Automation Platform's automation-controller. A user
with the delegated Instance Group Admin role on a container group can set a free-form
pod specification override that is deep-merged, without filtering, into every job pod
launched on that group. The only hardening applied is forcing
automountServiceAccountToken to false, which does not remove an explicitly declared
projected serviceAccountToken volume or secret volume mounts. A non-superuser can
therefore cause the kubelet to mint a ServiceAccount token for the control-plane
automation-controller service account into the job container and mount arbitrary
secrets from the control-plane namespace, obtaining the control-plane service-account
identity on the Kubernetes API and cleartext control-plane secrets (including the
platform database password and Django SECRET_KEY), leading to full platform data
compromise. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The bulk job launch endpoint builds workflow job nodes from client
input using a serializer that leaves the node's job reference -- a field normally
set by the workflow task manager after it spawns a child job -- writable and does
not include it in the permission validation performed for the other node fields.
An authenticated user with permission to execute a single job template can submit
a bulk job launch whose node references the identifier of any unified job in any
organization, including jobs they cannot access. The node then exposes that job's
metadata, and cancelling the attacker's workflow cancels the referenced job
through the workflow cancellation cascade, without any per-job authorization
check. Repeated, this allows a low-privileged user to cancel running jobs,
project and inventory syncs, ad hoc commands, and system jobs across all
organizations, denying automation service platform-wide. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-controller.
The execute-permission check on a workflow job template node's unified job
template is skipped when the node's currently stored unified job template is
empty: the check inspects only the existing value, not the incoming one, and a
node can be created without a unified job template. An authenticated user who
holds admin permission on a single workflow job template can create an empty node
and then patch it to reference any job template, project, inventory source,
system job, or workflow on the platform -- including ones in other organizations
that they cannot otherwise read or launch. Running their own workflow then
executes the victim template with the victim's attached credentials, inventory
and project, resulting in cross-organization privilege escalation to arbitrary
automation execution. The patch response also discloses the victim template's
name and description. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The Thycotic Secret Server external credential plugin passes a
user-supplied server URL to its SDK without validating the scheme, host, or IP
range, and the plugin backend is executed synchronously within the automation
controller web process. Using the external credential test endpoint, a user who
holds only the use role on such a credential can override the stored server URL
with an arbitrary internal address, causing the control plane to issue requests
to internal services. Although the response is a generic error, response timing
reveals whether internal hosts and ports are reachable, enabling internal
network reconnaissance and a blind request-forgery primitive from the control
plane, and each request can hold a web worker, affecting availability. |
| A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0. |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). |
| Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a maliciously formed field.
This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120 and Archer AX12 v1.0: up to 1.5.1 Build 20260721. |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L). |
| NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename derived from basename() of the URL. This operation requires no authentication. |
| A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of a per-connection queue, consuming excessive memory. Eventually, this can cause the Java Virtual Machine (JVM) to exhaust its heap, resulting in a Denial of Service (DoS) for the affected server. |
| A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY connection and send a large number of SYN_STREAM frames with FLAG_FIN=0, causing unbounded heap and direct memory allocation that can lead to JVM OutOfMemoryError and a denial of service. |
| Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key. |
| Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate uses find_cart_for_association to locate a cart by prefixed_id but does not require a cart token or otherwise verify possession of the selected guest cart. An authenticated customer can derive reversible prefixed cart IDs, associate an eligible guest cart with the attacker's account, and receive billing and shipping address data from the cart. Exploitation requires a guest cart with address data on a store that does not require login for checkout, and reassignment can also disrupt the guest's in-progress cart. This issue is fixed in versions 5.4.4 and 5.5.4. |
| Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed. |