RHEL 10 / 9:Red Hat Ansible 自動化平台 2.6 產品安全性與錯誤修正更新 (重大) (RHSA-2026:71113)

high Nessus Plugin ID 349536

概要

遠端 Red Hat 主機缺少一個或多個安全性更新。

說明

遠端 Redhat Enterprise Linux 10/9 主機上安裝的套件受到 RHSA-2026:71113 公告中提及的多個弱點影響。

Red Hat Ansible Automation Platform 提供企業架構,用於大規模構建、部署和管理 IT 自動化。IT 管理員可針對如何將自動化套用至個別團隊,提供自上而下的準則,自動化開發人員則可繼續自由撰寫利用現有知識的工作,而不會產生額外負荷。Ansible Automation Platform 可讓組織內的使用者透過簡單、功能強大且無代理程式的語言,共用、檢查和管理自動化內容。

安全性修正:

* automation-controller: GitPython:透過 Git 目錄模擬 (CVE-2026-87817) 執行遠端程式碼
* automation-controller:透過未經驗證的 Bitbucket Webhook oracle (CVE-2026-84717) 列舉任務範本
* automation-controller:透過 SystemJob extra_vars (CVE-2026-84724) 插入命令引數
* automation-controller:透過工作流程工作節點成品搜尋 (CVE-2026-84720) 洩露遮罩的憑證資料
* automation-controller:透過工作流程工作範本複製 (CVE-2026-84719) 進行執行個體群組權限提升
* automation-controller:透過不受限制的 X-Forwarded-For 信任 (CVE-2026-84718) 進行稽核記錄偽造
* automation-controller:透過安裝套件 () 為任意主機名稱頒發網格憑證 (CVE-2026-84716)
* automation-controller:透過 sanitize_jinja regex 繞過 (CVE-2026-84714) 插入範本
* automation-controller:透過未經驗證的 ping 端點 (CVE-2026-84712) 揭露自動化網狀拓撲
* automation-controller:透過 Project scm_branch git 引數插入 (CVE-2026-84711) 讀取的任意檔案
* automation-controller:透過憑證類型插入器 Jinja 轉譯 (CVE-2026-84709) 造成拒絕服務
* automation-controller:透過容器群組 Pod 規格覆寫 (CVE-2026-84708) 洩露控制層密碼
* automation-controller:透過主機篩選查詢遊走 (CVE-2026-84707) 未經授權的工作輸出洩露
* automation-controller:透過憑證類型 environment-injector blocklist bypass (CVE-2026-84706) 執行程式碼
* automation-controller:透過執行環境繫結 (CVE-2026-84703) 跨租用戶憑證洩露
* automation-controller:透過工作流程工作範本節點修補程式 (CVE-2026-84692) 繞過跨租用戶執行權限
* automation-controller:透過格式字串插入 (CVE-2026-84691) 洩漏私密金鑰和資料庫憑證
* automation-controller:透過大量工作啟動節點參照 (CVE-2026-84689) 的跨租用戶工作劫持
* automation-controller:透過通知範本類型切換重播 (CVE-2026-84686) 揭露憑證權杖
* automation-controller:透過建構的清單附件 (CVE-2026-84684) 進行權限提升
* automation-controller:透過 ANSI 超連結序列儲存在工作輸出 (CVE-2026-84683) 中的跨網站指令碼
* automation-controller:透過組織 Galaxy 憑證附件 (CVE-2026-84680) 進行憑證使用權限提升
* automation-controller:透過AWX_TASK_ENV設定 (CVE-2026-84679) 插入任意環境變數
* automation-controller:透過 Thycotic Secret Server 憑證測試 () 的伺服器端要求偽造 (CVE-2026-84644)
* automation-controller:透過專案簽章驗證繫結 (CVE-2026-84643) 跨組織憑證公開
* automation-controller:透過排程和工作流程節點附件 (CVE-2026-84638) 進行執行個體群組權限提升
* automation-controller:透過 Project scm_url git 引數插入 (CVE-2026-84502) 進行遠端程式碼執行
* automation-controller:透過驗證錯誤訊息 (CVE-2026-84499) 洩露調查密碼
* automation-controller: 未經驗證的排程器觸發程式端點暴露 (迴歸) (CVE-2026-84486)
* automation-controller:透過 provisioning-callback host-match bypass (CVE-2026-84474) 進行權限提升
* automation-controller:透過大量工作啟動權限檢查 (CVE-2026-84470) 進行執行個體群組權限提升
* automation-controller: GitPython:透過 TagReference.create() (CVE-2026-78679) 讀取的任意檔案
* automation-controller: awx:透過容器群組中的 pod_spec_override 插入,將權限提升至 OpenShift 命名空間 (CVE-2026-75884)
* automation-controller:透過臨機操作命令限制欄位 (CVE-2026-71465) 插入命令列引數
* automation-controller:透過排程scm_branch提示 (CVE-2026-71464) 繞過 Git 引數插入保護
* automation-controller:透過 notification-template Jinja 白名單繞過 (CVE-2026-71463) 揭露堆疊追蹤
* automation-controller:透過CUSTOM_VENV_PATHS驗證 (CVE-2026-71462) 的檔案系統路徑存在 oracle
* automation-controller:透過缺少 RBAC 檢查 () 而洩露跨租用戶工作事件資料 (CVE-2026-71459)
* automation-controller:透過 Named-URL 404 回應 oracle (CVE-2026-71458) 進行跨租用戶資源列舉
* automation-controller:無限制的訂閱和授權資訊洩露 (CVE-2026-71460)
* automation-controller: GitPython:透過 Git 選項前綴縮寫 (CVE-2026-67325) 進行命令插入
* automation-controller: GitPython:由於無人保護的 Git 選項,透過命令插入執行任意程式碼 (CVE-2026-67323)
* automation-controller: GitPython: 透過攻擊者控制的複製 URL (CVE-2026-67322) 洩漏環境變數
* automation-controller:透過 HashiCorp Vault 憑證 SSRF (CVE-2026-12564) 洩漏 Kubernetes 服務帳戶權杖
* automation-gateway-proxy: Golang MIME:透過惡意製作的 MIME 標頭 (CVE-2026-42504) 造成拒絕服務
* automation-gateway-proxy: golang net/url: 路徑解析中的二次複雜度導致的拒絕服務 (CVE-2026-56860)
* automation-gateway-proxy:轉至 encoding/asn1:透過 Unmarshal (CVE-2026-33818) 中的過度遞迴造成拒絕服務
* automation-gateway-proxy: Golang crypto/tls:透過無限期 KeyUpdate 訊息 (CVE-2026-56862) 造成拒絕服務
* automation-gateway-proxy:前往 html/template:透過病理輸入 (CVE-2026-56858) 進行跨網站指令碼
* automation-platform-ui: js-yaml: YAML 剖析中的拒絕服務弱點 (CVE-2026-84375)
* automation-platform-ui: DOMPurify:透過IN_PLACE清理 (CVE-2026-75838) 進行跨網站指令碼
* automation-platform-ui: nanoid:透過在非安全模組函式中輸入負大小而造成拒絕服務 (CVE-2026-67214)
* automation-platform-ui: nanoid:由於整數溢位 (CVE-2026-73086) 而產生可預測的 ID
* automation-platform-ui: PostCSS:透過特製的 sourceMappingURL (CVE-2026-69153) 進行資訊洩露
* automation-platform-ui: js-yaml:透過特製的 YAML 文件造成拒絕服務 (CVE-2026-59869)
* python-sqlparse:透過 SQL 剖析中的二次 CPU 消耗造成拒絕服務 (CVE-2026-54284)
* python-sqlparse:透過低效的 SQL 剖析造成拒絕服務 (CVE-2026-59893)
* python-sqlparse:透過註解分組中的二次 CPU 消耗造成拒絕服務 (CVE-2026-71491)
* python3.12-gitpython:透過 Git 目錄模擬 (CVE-2026-87817) 進行遠端程式碼執行
* python3.12-sqlparse:透過 SQL 剖析中的二次 CPU 消耗造成拒絕服務 (CVE-2026-54284)
* python3.12-sqlparse:透過低效的 SQL 剖析造成拒絕服務 (CVE-2026-59893)
* python3.12-sqlparse:透過註解分組中的二次 CPU 消耗造成拒絕服務 (CVE-2026-71491)
* 接收器:Golang crypto/tls:透過無限期 KeyUpdate 訊息 (CVE-2026-56862) 造成拒絕服務
* 接收器:Go:透過 XML 解碼遞迴深度問題造成拒絕服務 (CVE-2026-56859)
* 接收器:golang net/url:路徑解析中的二次複雜度導致的拒絕服務 (CVE-2026-56860)
* receptor: Go encoding/asn1:透過 Unmarshal 中過度遞迴造成的拒絕服務 (CVE-2026-33818)
* 受體:Go html/template:透過病理輸入的跨站腳本 (CVE-2026-56858)
* 接收器:Go net/http:未加密的 HTTP/2 連線容易受到拒絕服務 (CVE-2026-56853)

如需安全性問題的詳細資料,包括影響、CVSS 評分、致謝及其他相關資訊,請參閱〈參照〉一節列出的 CVE 頁面。

請參閱「參考資源」一節中列出的版本資訊,瞭解有關此版本的詳細資料。

Tenable 已直接從 Red Hat Enterprise Linux 安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

更新受影響的套件。

另請參閱

https://access.redhat.com/errata/RHSA-2026:71113

https://access.redhat.com/security/updates/classification/#critical

https://bugzilla.redhat.com/show_bug.cgi?id=2484204

https://bugzilla.redhat.com/show_bug.cgi?id=2490556

https://bugzilla.redhat.com/show_bug.cgi?id=2498122

https://bugzilla.redhat.com/show_bug.cgi?id=2508411

https://bugzilla.redhat.com/show_bug.cgi?id=2509975

https://bugzilla.redhat.com/show_bug.cgi?id=2509976

https://bugzilla.redhat.com/show_bug.cgi?id=2510021

https://bugzilla.redhat.com/show_bug.cgi?id=2510719

https://bugzilla.redhat.com/show_bug.cgi?id=2512367

https://bugzilla.redhat.com/show_bug.cgi?id=2512368

https://bugzilla.redhat.com/show_bug.cgi?id=2512369

https://bugzilla.redhat.com/show_bug.cgi?id=2512371

https://bugzilla.redhat.com/show_bug.cgi?id=2512372

https://bugzilla.redhat.com/show_bug.cgi?id=2512374

https://bugzilla.redhat.com/show_bug.cgi?id=2512375

https://bugzilla.redhat.com/show_bug.cgi?id=2514175

https://bugzilla.redhat.com/show_bug.cgi?id=2515815

https://bugzilla.redhat.com/show_bug.cgi?id=2515820

https://bugzilla.redhat.com/show_bug.cgi?id=2515827

https://bugzilla.redhat.com/show_bug.cgi?id=2515838

https://bugzilla.redhat.com/show_bug.cgi?id=2515839

https://bugzilla.redhat.com/show_bug.cgi?id=2515840

https://bugzilla.redhat.com/show_bug.cgi?id=2517518

https://bugzilla.redhat.com/show_bug.cgi?id=2517523

https://bugzilla.redhat.com/show_bug.cgi?id=2517527

https://bugzilla.redhat.com/show_bug.cgi?id=2517772

https://bugzilla.redhat.com/show_bug.cgi?id=2517893

https://bugzilla.redhat.com/show_bug.cgi?id=2523205

https://bugzilla.redhat.com/show_bug.cgi?id=2527046

https://bugzilla.redhat.com/show_bug.cgi?id=2527073

https://bugzilla.redhat.com/show_bug.cgi?id=2527085

https://bugzilla.redhat.com/show_bug.cgi?id=2527090

https://bugzilla.redhat.com/show_bug.cgi?id=2527096

https://bugzilla.redhat.com/show_bug.cgi?id=2527100

https://bugzilla.redhat.com/show_bug.cgi?id=2527112

https://bugzilla.redhat.com/show_bug.cgi?id=2527117

https://bugzilla.redhat.com/show_bug.cgi?id=2527118

https://bugzilla.redhat.com/show_bug.cgi?id=2527123

https://bugzilla.redhat.com/show_bug.cgi?id=2527126

https://bugzilla.redhat.com/show_bug.cgi?id=2527128

https://bugzilla.redhat.com/show_bug.cgi?id=2527139

https://bugzilla.redhat.com/show_bug.cgi?id=2527140

https://bugzilla.redhat.com/show_bug.cgi?id=2527145

https://bugzilla.redhat.com/show_bug.cgi?id=2527151

https://bugzilla.redhat.com/show_bug.cgi?id=2527154

https://bugzilla.redhat.com/show_bug.cgi?id=2527156

https://bugzilla.redhat.com/show_bug.cgi?id=2527187

https://bugzilla.redhat.com/show_bug.cgi?id=2527189

https://bugzilla.redhat.com/show_bug.cgi?id=2527190

https://bugzilla.redhat.com/show_bug.cgi?id=2527191

https://bugzilla.redhat.com/show_bug.cgi?id=2527195

https://bugzilla.redhat.com/show_bug.cgi?id=2527196

https://bugzilla.redhat.com/show_bug.cgi?id=2527198

https://bugzilla.redhat.com/show_bug.cgi?id=2527199

https://bugzilla.redhat.com/show_bug.cgi?id=2527210

https://bugzilla.redhat.com/show_bug.cgi?id=2527211

https://bugzilla.redhat.com/show_bug.cgi?id=2527213

https://bugzilla.redhat.com/show_bug.cgi?id=2527214

https://bugzilla.redhat.com/show_bug.cgi?id=2527222

https://bugzilla.redhat.com/show_bug.cgi?id=2530744

http://www.nessus.org/u?2242e607

http://www.nessus.org/u?89e9dbff

http://www.nessus.org/u?8dc1306c

Plugin 詳細資訊

嚴重性: High

ID: 349536

檔案名稱: redhat-RHSA-2026-71113.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/9/23

已更新: 2026/9/23

支援的感應器: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 5.7

百分位數: 96.05

Vendor

Vendor Severity: Critical

CVSS v2

風險因素: Medium

基本分數: 5

時間性分數: 3.9

媒介: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS 評分資料來源: CVE-2026-69153

CVSS v3

風險因素: Medium

基本分數: 5.3

時間性分數: 4.8

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

風險因素: High

Base Score: 8.7

Threat Score: 7.4

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS 評分資料來源: CVE-2026-87817

弱點資訊

CPE: cpe:/o:redhat:enterprise_linux:10, cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:redhat:enterprise_linux:automation-controller-cli, p-cpe:/a:redhat:enterprise_linux:automation-controller-server, p-cpe:/a:redhat:enterprise_linux:automation-controller-ui, p-cpe:/a:redhat:enterprise_linux:automation-controller-venv-tower, p-cpe:/a:redhat:enterprise_linux:automation-controller, p-cpe:/a:redhat:enterprise_linux:automation-gateway-proxy-server, p-cpe:/a:redhat:enterprise_linux:automation-platform-ui, p-cpe:/a:redhat:enterprise_linux:python-sqlparse, p-cpe:/a:redhat:enterprise_linux:python3-sqlparse, p-cpe:/a:redhat:enterprise_linux:python3.12-gitpython, p-cpe:/a:redhat:enterprise_linux:python3.12-sqlparse, p-cpe:/a:redhat:enterprise_linux:receptor

必要的 KB 項目: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/9/23

弱點發布日期: 2026/6/2

參考資訊

CVE: CVE-2026-12564, CVE-2026-33818, CVE-2026-42504, CVE-2026-54284, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-59869, CVE-2026-59893, CVE-2026-67214, CVE-2026-67322, CVE-2026-67323, CVE-2026-67325, CVE-2026-69153, CVE-2026-71458, CVE-2026-71459, CVE-2026-71460, CVE-2026-71462, CVE-2026-71463, CVE-2026-71464, CVE-2026-71465, CVE-2026-71491, CVE-2026-73086, CVE-2026-75838, CVE-2026-75884, CVE-2026-78679, CVE-2026-84375, CVE-2026-84470, CVE-2026-84474, CVE-2026-84486, CVE-2026-84499, CVE-2026-84502, CVE-2026-84638, CVE-2026-84643, CVE-2026-84644, CVE-2026-84679, CVE-2026-84680, CVE-2026-84683, CVE-2026-84684, CVE-2026-84686, CVE-2026-84689, CVE-2026-84691, CVE-2026-84692, CVE-2026-84703, CVE-2026-84706, CVE-2026-84707, CVE-2026-84708, CVE-2026-84709, CVE-2026-84711, CVE-2026-84712, CVE-2026-84714, CVE-2026-84716, CVE-2026-84717, CVE-2026-84718, CVE-2026-84719, CVE-2026-84720, CVE-2026-84724, CVE-2026-87817

CWE: 1050, 1241, 1333, 134, 15, 184, 204, 209, 214, 22, 266, 348, 489, 497, 522, 606, 639, 770, 776, 78, 79, 807, 835, 839, 862, 863, 88, 915, 918

RHSA: 2026:71113