CVE-2024-1657

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system.
Configurations

No configuration.

History

21 Nov 2024, 08:51

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en the ansible automation platform. Se estaba utilizando una conexión WebSocket insegura en la instalación desde el servidor EDA del libro de reglas de Ansible. Un atacante que tenga acceso a cualquier máquina en el bloque CIDR podría descargar todos los datos del libro de reglas del WebSocket, lo que resultaría en la pérdida de confidencialidad e integridad del sistema.
References () https://access.redhat.com/errata/RHSA-2024:1057 - () https://access.redhat.com/errata/RHSA-2024:1057 -
References () https://access.redhat.com/security/cve/CVE-2024-1657 - () https://access.redhat.com/security/cve/CVE-2024-1657 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2265085 - () https://bugzilla.redhat.com/show_bug.cgi?id=2265085 -

25 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-25 17:15

Updated : 2024-11-21 08:51


NVD link : CVE-2024-1657

Mitre link : CVE-2024-1657

CVE.ORG link : CVE-2024-1657


JSON object : View

Products Affected

No product.

CWE
CWE-1385

Missing Origin Validation in WebSockets