Impact
A server‑side request forgery flaw in Galaxy_ng, the Ansible Galaxy plugin for Pulp, allows authenticated users with namespace‑management permissions to set an arbitrary avatar URL. The background worker fetches that URL without validating the destination or enforcing a timeout, enabling the attacker to reach internal IP ranges, loopback addresses, or cloud instance‑metadata endpoints. This exposure can be used to enumerate internal services and, if a slow or non‑responsive target is requested, can pin workers and trigger a denial of service.
Affected Systems
The vulnerability affects Red Hat Ansible Automation Platform 2, specifically the Galaxy_ng in that distribution. No additional version qualifiers are listed beyond the product edition.
Risk and Exploitability
The CVSS score of 6.4 signifies moderate severity, while the lack of an EPSS value and the absence from the CISA KEV catalog suggest limited publicly documented exploitation but do not preclude risk. Attackers need only authorization with namespace‑management rights; they then can probe private networks or metadata services for further information, potentially exposing secrets. Successful exploitation may result in internal network discovery and denial of service due to worker pinning, depending on the target chosen.
OpenCVE Enrichment