Product
An SSRF vulnerability in the AWX webhook status callback mechanism allows attackers with template-level administrative access to exfiltrate Git Personal Access Tokens via forged webhook payloads.