漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Awx: websocket eventconsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure
Vulnerability Description
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_update_events, project_update_events, and system_job_events — are not mapped, causing the authorization check to be skipped. Any authenticated user can subscribe to these unmapped websocket event groups for any object ID and receive real-time stdout output from jobs belonging to organizations they have no access to. This is an incomplete remediation of CVE-2020-10698.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
Red Hat Ansible Automation Platform 2 授权问题漏洞
Vulnerability Description
Red Hat Ansible Automation Platform 2是美国Red Hat公司的一款构建、部署和管理自动化的软件。 Red Hat Ansible Automation Platform 2存在授权问题漏洞,该漏洞源于AWX中websocket事件消费者未对inventory_update_events、project_update_events和system_job_events三个事件组进行RBAC授权检查,可能导致任何已认证用户订阅这些未映射的websocket事件组,并接收来自
CVSS Information
N/A
Vulnerability Type
N/A