Ad

CVE-2026-84717

MEDIUM CVSS 3.1: 5,3 EPSS 0.34%
Обновлено 27 сентября 2026
Red Hat
Параметр Значение
CVSS 5,3 (MEDIUM)
Тип уязвимости CWE-204
Поставщик Red Hat
Публичный эксплойт Нет

A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook configured and HTTP 403 otherwise. An unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without knowing the secret webhook_key.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Низкая
Легко эксплуатировать
Нужны права
Не требуются
Права не нужны
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Низкое
Частичная утечка данных
Целостность
Нет
Нет модификации данных
Доступность
Нет
Нет нарушения работы

Строка CVSS v3.1

Тип уязвимости (CWE)

Уязвимые продукты

red hat:red hat ansible automation platform 2.7 red hat:red hat ansible automation platform 2.6 for rhel 9 red hat:red hat ansible automation platform 2.6 red hat:red hat ansible automation platform 2.5 for rhel 8 red hat:red hat ansible automation platform 2.5 for rhel 9