W komponencie tworzenia tras Red Hat Ansible Automation Platform Gateway odkryto lukę umożliwiającą kradzież poświadczeń poprzez tworzenie mylących tras z podwójnym ukośnikiem (//) w gateway_path. Złośliwy lub socjotechnicznie manipulowany administrator może skonfigurować trasę pułapki do przechwytu i eksfiltracji poświadczeń użytkowników, potencjalnie zachowując trwały dostęp lub tworząc backdoor nawet po wycofaniu jego uprawnień.
▸ Pokaż oryginał (EN)
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HRed Hat Ansible Automation Platform
APPRedhat< 2.6Red Hat Ansible Developer
APPRedhat1.21.3Red Hat Ansible Inside
APPRedhat1.31.4Red Hat Enterprise Linux
OSRedhat8.09.0
Powiązane podatności
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
RCE przez EL injection w RichFaces Framework 3.X — brak uwierzytelnienia
GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)
ShellShock — RCE poprzez zmienne środowiskowe w GNU Bash