Database/Control plane, storage & DevOps
Ansible automation-controller: Bitbucket DC webhook ping skips HMAC check, enumerating webhook-enabled templates
Impact
The unauthenticated Bitbucket Data Center webhook receiver looks up the target template before deciding to skip HMAC signature verification for diagnostics:ping events, so it answers HTTP 200 for templates that have a Bitbucket DC webhook configured and HTTP 403 for everything else. That difference is an oracle: an unauthenticated caller can walk Job Template and Workflow Job Template IDs and learn which ones are webhook-triggered, without knowing webhook_key. It leaks nothing but structure, yet it tells an attacker exactly which automation entry points are worth attacking next on a controller that drives fleet configuration. Confidentiality impact is low and there is no integrity or availability effect.
Who can reach it
Anyone who can reach the automation-controller webhook endpoint over the network, with no credentials and no webhook secret. Exposure depends on whether the controller's webhook path is reachable beyond your Bitbucket instance.
What to do
Apply the automation-controller errata (RHSA-2026:71113, 71114, 71177, 71179) for your AAP channel and restart the controller services; no node drain. Where patching must wait, restrict the webhook endpoint at the ingress to your Bitbucket Data Center source addresses.
References
Related entries
- DMTF libspdm CSR generation under the mbedTLS crypto backend (cryptlib_mbedtls): Stack corruption inside the firmwareNCVD-2026-006-dmtf-libspdm-csr-generation-unde · DMTF libspdm CSR generation under the mbedTLS crypto backend (cryptlib_mbedtls)Medium
- DMTF libspdm responder handling of GET_MEASUREMENT_EXTENSION_LOG: A requester reads memory it was never authorisedNCVD-2026-007-dmtf-libspdm-responder-handling · DMTF libspdm responder handling of GET_MEASUREMENT_EXTENSION_LOGMedium
- rclone (rc server, /debug/pprof handler): The pprof debug handler is mounted as its own route on the rcloneNCVD-2026-041-rclone-rc-server-debug-pprof-han · rclone (rc server, /debug/pprof handler)Medium
- Keycloak: OIDC authentication flaw - attacker reusing data from a same-realm request impersonates a userCVE-2023-0264 · KeycloakMedium
- MySQL Server: InnoDB flaw allowing a high-privileged network attacker to cause a repeatable DoSCVE-2022-21417 · MySQL ServerMedium
- MySQL Server: InnoDB flaw - a high-privileged network attacker can hang or repeatedly crash the serverCVE-2023-22084 · MySQL ServerMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.