PT-2026-89097 · Red Hat · Red Hat Ceph Storage 5+3
CVE-2026-87872
·
Publicado
2026-09-09
·
Atualizado
2026-09-09
CVSS v3.1
6.8
Média
| Vetor | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
A flaw was found in the OCAPI modules (ocapi command, ocapi info) of the
community.general Ansible collection. The shared OCAPI request helper disables
TLS certificate validation on every request and the modules expose no parameter
to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint.
An attacker positioned on the network path between the Ansible controller and the
OCAPI-managed storage/enclosure device can present any certificate, intercept the
session, capture the credentials, and tamper with responses.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat Ceph Storage 5
Red Hat Ceph Storage 9
Red Hat Openstack Platform 17.1
Red Hat Openstack Platform 18.0