PT-2026-97436 · Red Hat · Red Hat Ansible Automation Platform 2+5
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
The
JobJobEventsChildrenSummary view lacks a defined model or parent model, causing the ModelAccessPermission.check get permissions() function to return True for any authenticated user. Because the view utilizes get object or 404(Job, pk) without implementing Django Rest Framework (DRF) object-level permission checks, an authenticated user with zero privileges can access the event tree structure and the event processing finished status. Additionally, this allows for the enumeration of Job IDs across the platform using a 200/404 oracle, where the server response indicates whether a specific ID exists. This occurs while the sibling endpoint '/jobs/{id}/job events/' correctly enforces permissions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Ansible Automation Platform 2
Red Hat Ansible Automation Platform 2.5 For Rhel 8
Red Hat Ansible Automation Platform 2.5 For Rhel 9
Red Hat Ansible Automation Platform 2.6
Red Hat Ansible Automation Platform 2.6 For Rhel 9
Red Hat Ansible Automation Platform 2.7