6.7 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @anthonyroussel Activity log
- Created suggestion
- @anthonyroussel dismissed
Event-driven-ansible: event stream test mode exposes sensitive headers in aap eda
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.
References
Affected products
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
Matching in nixpkgs
pkgs.molecule
Aids in the development and testing of Ansible roles
pkgs.ansible-lint
Best practices checker for Ansible
pkgs.ansible-builder
Ansible execution environment builder
pkgs.ansible-navigator
Text-based user interface (TUI) for Ansible
pkgs.python312Packages.bindep
None
pkgs.python313Packages.bindep
Bindep is a tool for checking the presence of binary packages needed to use an application / library
pkgs.python314Packages.bindep
Bindep is a tool for checking the presence of binary packages needed to use an application / library
pkgs.python312Packages.molecule
None
pkgs.python313Packages.molecule
Aids in the development and testing of Ansible roles
pkgs.python314Packages.molecule
Aids in the development and testing of Ansible roles
pkgs.python312Packages.ansible-builder
None
pkgs.python313Packages.ansible-builder
Ansible execution environment builder
pkgs.python314Packages.ansible-builder
Ansible execution environment builder
pkgs.python312Packages.molecule-plugins
None
pkgs.python313Packages.molecule-plugins
Collection on molecule plugins
pkgs.python314Packages.molecule-plugins
Collection on molecule plugins
Package maintainers
-
@Melkor333 Samuel Ruprecht <samuel@ton-kunst.ch>
-
@HarisDotParis Haris <git@haris.paris>
-
@sengaya Thilo Uttendorfer <tlo@sengaya.de>
-
@robsliwi Robert Sliwinski <r@sliwi.org>
-
@anthonyroussel Anthony Roussel <anthony@roussel.dev>
-
@vinetos vinetos <contact+git@vinetos.fr>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>