Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

81 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.3)0.41%—Redhat Ansible Automation PlatformAI17/4/202617/6/2026
A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker to inject control characters such as…
ModificadaMedia (6.4)0.18%—Redhat Ansible Automation Platform8/4/202624/9/2026
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root…
AnalizadaMedia (6.7)0.17%—Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside27/2/202617/6/2026
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to…
AnalizadaMedia (6.7)0.20%—Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside27/2/202617/6/2026
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By…
AnalizadaMedia (6.7)0.17%—Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside27/2/202617/6/2026
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of…
AplazadaAlta (8.5)0.42%—Redhat Ansible Automation PlatformAI8/1/202617/6/2026
A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g., Controller, Hub, EDA). If this flaw were…
AnalizadaCrítica (9.1)0.74%—Accela Automation Platform19/9/202517/6/2026
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for arbitrary file write and server-side request…
AplazadaMedia (4.4)0.22%—Ansible Automation PlatformAI31/7/202517/6/2026
A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text…
AnalizadaBaja (3.5)0.19%—Redhat Ansible Automation Platform11/7/202517/6/2026
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
AnalizadaBaja (3.1)0.11%—Redhat Ansible Automation Platform11/7/202517/6/2026
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.
AplazadaAlta (8.8)0.58%—Redhat Ansible Automation PlatformAI30/6/202517/6/2026
A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead…
AplazadaAlta (8.8)0.61%—Redhat Ansible Automation PlatformAIRedhat EDAAI30/6/202517/6/2026
A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows an authenticated attacker to inject arguments and execute arbitrary commands on the EDA worker. In Kubernetes/OpenShift environments, this can lead…
AplazadaMedia (6.5)0.41%—Redhat Ansible Automation PlatformAIRedhat Event Driven AnsibleAIRedhat Event StreamsAI28/3/202517/6/2026
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.
AplazadaMedia (5)0.53%—Ansible Automation PlatformAI25/11/202417/6/2026
A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on ansible_base.oauth2_provider for OAuth2 authentication. While the impact is…
ModificadaMedia (6.1)0.40%—Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside16/10/202417/6/2026
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data.
AplazadaMedia (5.3)0.16%—Redhat Ansible Automation PlatformAIRedhat Event Driven AutomationAI8/10/202417/6/2026
A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transmitted between the EDA and AAP. An attacker with system access could exploit this…
AplazadaAlta (8.1)0.38%—Ansible Automation PlatformAIAnsible Rulebook EDA ServerAI25/4/202417/6/2026
A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity…
ModificadaMedia (5.5)0.30%—Redhat AnsibleRedhat Enterprise LinuxRedhat Ansible Automation PlatformRedhat Ansible Developer+26/2/202417/6/2026
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
ModificadaAlta (7.5)1.1%—Redhat Ansible Automation PlatformRedhat Enterprise LinuxRedhat Update InfrastructureCryptography.io Cryptography+15/2/202417/6/2026
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
ModificadaMedia (6.3)1.0%—Redhat Ansible Automation PlatformRedhat Ansible InsideRedhat Ansible DeveloperDebian Linux18/12/202317/6/2026
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
ModificadaAlta (7.8)0.54%—Redhat AnsibleFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Ansible Automation Platform+212/12/202317/6/2026
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
ModificadaMedia (6.5)0.98%—Redhat Ansible Automation PlatformRedhat Satellite14/11/202317/6/2026
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (6.3)0.64%—Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside4/10/202317/6/2026
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
ModificadaAlta (7.8)0.25%—Redhat Ansible Automation PlatformRedhat Ansible Collection4/10/202317/6/2026
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.