PT-2023-4750 · Red Hat · Red Hat Ansible
CVE-2023-4567
·
Publicado
2023-08-28
·
Atualizado
2026-03-22
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat Ansible (affected versions not specified)
Description
The issue is related to the lack of protection of the SQL query structure in Red Hat Ansible's configuration management system. Exploitation of this issue could allow a remote attacker to impact the integrity and availability of protected information using the
SOCIAL AUTH GITHUB KEY parameter in the "/api/v2/settings/all/" endpoint.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat Ansible