Threats Tagged 'ghsa-p5f2-j2p5-7p7v'
View all threats tagged with 'ghsa-p5f2-j2p5-7p7v'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-p5f2-j2p5-7p7v'
Click on any threat for detailed analysis and mitigation recommendations
0 A critical vulnerability (CVE-2026-12564) exists in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function improperly sends the Kubernetes service account token to an attacker-controlled URL when testing a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication. This allows an authenticated attacker with credential-creation privileges to exfiltrate the token and gain Kubernetes API access with full pod CRUD and secret read permissions, including sensitive credentials and the Django SECRET_KEY. A fix is available from Red Hat in Ansible Automation Platform 2.7. Join the discussion | GCVE Database | 08/18/2026, 18:31:57 UTC Added: 09/24/2026, 06:07:31 UTC |
Showing 1 to 1 of 1 result