目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2025-9908— Red Hat Ansible Automation Platform 安全漏洞

CVSS 6.7 · Medium EPSS 0.00% · P0
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-9908の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Event-driven-ansible: sensitive internal headers disclosure in aap eda event streams
ソース: NVD (National Vulnerability Database)
脆弱性説明
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By exfiltrating these headers, an attacker could spoof trusted requests, escalate privileges, or perform malicious event injection.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
信息暴露
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Red Hat Ansible Automation Platform 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Red Hat Ansible Automation Platform(Red Hat AAP)是美国红帽(Red Hat)公司的一款实现战略性自动化的统一解决方案。 Red Hat Ansible Automation Platform(Red Hat AAP)存在安全漏洞,该漏洞源于可通过EDA Event Streams Internal Headers绕过访问限制,可能导致读取敏感信息。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:3.1.1-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.2-1.1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:0.1.4-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:1.1.14-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.10.10-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:2.13.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:0.4.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.2.26-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:2.1.2-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:0.4.36-2.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.10.10-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:23.0.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:1.6.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:9.0.1-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:3.8.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:0.2.15-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:0.4.2-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.0-1.2.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.15.0-1.el8ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:3.1.1-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:25.12.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:25.12.2-1.1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:25.12.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:25.12.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:25.12.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:0.1.4-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:1.1.14-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:4.10.10-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:2.13.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:25.12.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:25.12.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:0.4.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:4.2.26-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:2.1.2-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:0.4.36-2.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:4.10.10-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:23.0.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:1.6.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:9.0.1-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:25.12.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:3.8.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:0.2.15-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:0.4.2-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:25.12.0-1.2.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9 0:4.15.0-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el9
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9 0:1.2.1-1.el9ap ~ * cpe:/a:redhat:ansible_automation_platform_inside:2.6::el9
Red HatRed Hat Ansible Automation Platform 2.5 sha256:07673470fb62db8bec12ec20b2500228c0c6d5108916dd936d91e10610b783d1 ~ * cpe:/a:redhat:ansible_automation_platform:2.5::el8
Red HatRed Hat Ansible Automation Platform 2.6 sha256:142125ce7f176ce4d9755f3124714bbfd8e10a687378988761d5451bd135ca76 ~ * cpe:/a:redhat:ansible_automation_platform:2.6::el9

II. CVE-2025-9908の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-9908のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Red Hat · 2026-02-27 · 5 CVEs total

CVE-2026-09808.3 HIGHRubyipmi: red hat satellite: remote code execution in rubyipmi via malicious bmc username
CVE-2025-99096.7 MEDIUMAap-gateway: improper path validation in gateway allows credential exfiltration
CVE-2025-99076.7 MEDIUMEvent-driven-ansible: event stream test mode exposes sensitive headers in aap eda
CVE-2026-08714.9 MEDIUMOrg.keycloak/keycloak-services: keycloak: unauthorized modification of unmanaged user attr

IV. 関連脆弱性

V. CVE-2025-9908へのコメント

まだコメントはありません


コメントを残す