PT-2026-51010 · Red Hat · Red Hat Ansible Automation Platform 2
Publicado
2026-06-19
·
Atualizado
2026-06-19
·
CVE-2026-12726
CVSS v3.1
6.3
Média
| Vetor | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull request webhooks, the controller stores the pull request.statuses url value from the webhook payload without validating that it points to a trusted GitHub API endpoint. If a job template is configured with a GitHub Personal Access Token as its webhook credential, the controller later POSTs that token to the stored callback URL when posting job status updates. An attacker who can submit a correctly signed forged webhook using the job template's webhook key can redirect the callback to an attacker-controlled URL and exfiltrate the configured GitHub PAT.
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat Ansible Automation Platform 2