| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A flaw was found in the Ansible Automation Platform automation-controller. In the shipped
production configuration, the Controller trusts the client-supplied X-Forwarded-For header as
the request's client IP without verifying that it originated from a trusted proxy, and selects
the leftmost (attacker-controlled) header value. As a result, an attacker can forge the source
IP address recorded for their requests in the Controller's audit and access logs, degrading
the integrity of forensic and SIEM attribution. The flaw does not grant additional access. |
| A flaw was found in the automation-controller input-validation
guard sanitize_jinja(). The function uses two regular
expressions to reject user-supplied Jinja, but the patterns
stop at the first interior '}' or '%' character, so a Jinja
expression containing an inner brace (for example an empty
dict) is accepted while remaining valid Jinja. Because
sanitize_jinja() is the sole guard on several launch-time
fields — ad-hoc command module_args, Machine-credential
username / become_method / become_user, and inventory host
names — a low-privileged user can inject Jinja that ansible-core
evaluates in the execution environment. This enables execution
of arbitrary commands in the execution environment (bypassing an
administrator's AD_HOC_COMMANDS module allowlist) and disclosure
of secrets belonging to credentials the attacker cannot read
(by templating a co-attached credential's injected environment
variables), across the credential access-control boundary. |
| A flaw was found in the automation-controller API. The
unauthenticated health-check endpoint /api/v2/ping/
(ApiV2PingView, AllowAny) over-serializes RBAC-gated
automation-mesh data into its anonymous response, exposing the
full instance inventory (node hostnames, node types, UUIDs,
heartbeats, capacities, and exact versions), all instance-group
names and membership, the deployment install UUID, and the
active control node. A remote, unauthenticated attacker can use
this to map the control plane and fingerprint software versions
for targeted attacks. This flaw affects confidentiality only;
it does not expose secrets, credentials, or tenant data. |
| LaunchConfigurationBaseSerializer.scm_branch has no
validate_scm_branch() leading-dash check, unlike
Project/JobTemplate/JobLaunch serializers. Schedule and
WFJT Node accept --upload-pack=/bin/id as scm_branch.
Currently blocked at runtime by jobs.py:1502 ValueError
check (defense-in-depth), but the API validation gap
means sole reliance on a task-layer guard. Refactoring
that guard away would promote this to RCE. |
| RunAdHocCommand.build_args() appends limit as bare
positional (args.append(limit)) instead of using
args.extend(['-l', limit]) like RunJob. A limit beginning
with - is parsed as an ansible CLI option. Currently
limited to short-circuit flags (--version, --help) since
injected element displaces required pattern positional.
Would escalate if ansible-core ever defaults pattern. |
| A server-side request forgery flaw was found in the Ansible Automation Platform
automation-controller email notification backend. The email backend passes the user-supplied SMTP
host and port from a notification template directly to the SMTP client without validating that
the target is not an internal, loopback, link-local, or reserved address. An authenticated user
with organization notification-admin permission can create or modify an email notification
template pointing at an arbitrary internal address, trigger a test, and have the controller task
process open a raw TCP connection to that address. The resulting connection error is reflected
back through the notification record, providing a three-state internal port-scan oracle (open,
closed, filtered) over the control-plane's cluster network, including the in-cluster Kubernetes
API. When a shared organization template holds a stored SMTP password, redirecting the host can
also cause that credential to be transmitted to an attacker-controlled server. |
| A flaw was found in Ansible Automation Platform's automation-controller (AWX).
The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the
requested instance_groups with only a read-level permission check, whereas the
standard single-job launch path requires use-level permission on the same
field. A principal that holds read (but not use) permission on an instance
group -- for example the built-in read-only System Auditor role -- together
with execute permission on a job template can launch bulk jobs onto instance
groups they are not authorized to use, bypassing execution-placement
isolation. |
| StringListPathField.to_internal_value() calls
os.path.exists() on unbounded user-supplied paths.
200 vs 400 response reveals existence of arbitrary
absolute paths on the controller-web pod. Tenant
superuser can confirm /etc/tower/SECRET_KEY, k8s
service-account token, receptor sockets, ConfigMap
mount points. Mainly impactful on managed AAP
(ansiblecloud.com) where tenant admin != host admin. |
| /api/v2/config/ is protected only by IsAuthenticated.
license_info (account_number, subscription_id, pool_id,
sku, support_level, instance counts) returned to any
authenticated user. The superuser/auditor gate only covers
project_base_dir/project_local_paths/custom_virtualenvs,
not license_info. Enables social engineering against
Red Hat support and estate sizing reconnaissance. |
| URLModificationMiddleware resolves named-URL lookups
against unfiltered Model.objects before RBAC. The 403→404
shim only rewrites 403 responses, leaving the pk=0 miss
path with a different 404 detail string. Differential
"Not found." vs "No <Model> matches..." reveals whether
a named resource (org, credential, inventory, host) exists
anywhere on the platform. Enables cross-tenant internal
hostname enumeration. |
| A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container. |
| A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The setting that formats the log message emitted for API 4XX errors
is an administrator-controlled Python format-string template that is rendered
with a live user object as an argument. Because Python string formatting permits
attribute and item traversal on its arguments, an administrator can craft a
template that walks from the user object into the application settings and reads
the Django secret key and the database password. The formatted message is written
to a logger that can be forwarded to an external log aggregator, whose destination
is also administrator-controlled, allowing the secrets to be sent off the host. An
authenticated administrator can thereby obtain the master encryption key used to
protect all stored credentials and the database service password, enabling offline
decryption of every stored credential, forgery of user sessions, and direct
access to the controller database. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The Project scm_url field is not validated against values that
begin with a dash and is stored and passed verbatim to the git SCM module.
Because the module runs git ls-remote with the URL as a positional argument and
without a "--" separator, a git project URL such as "--upload-pack=<command>:x"
is interpreted by git as the --upload-pack option and executed via a shell. A
user with permission to create or modify a project in a single organization can
thereby execute arbitrary commands on the control-plane task pod, with output
reflected through the project update stdout endpoint, leading to cross-tenant
compromise and in-cluster lateral movement |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. Four debug views that trigger the internal task, dependency, and
workflow schedulers are configured to allow any user (including unauthenticated
clients) and are routed in production builds because their URL include is not
gated on the debug setting. An unauthenticated remote attacker can repeatedly
invoke these endpoints to acquire the cluster-wide scheduler advisory lock;
because the legitimate scheduler acquires the same lock without waiting, the
attacker causes real scheduler runs to be skipped, stalling job dispatch for
all tenants, while also consuming controller web workers. The debug root view
additionally discloses the list of debug endpoints to unauthenticated callers. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The provisioning-callback secret (host_config_key) is exposed to
users holding only the read-level view_jobtemplate permission -- both in the
job template API representation and in the activity stream -- and the
provisioning callback endpoint trusts a client-supplied X-Forwarded-For
header to determine the calling host when the controller is deployed behind
the AAP gateway with an empty proxy allow-list. By reading the secret and
spoofing X-Forwarded-For to match any host in the job template's inventory, a
minimally privileged or unauthenticated remote attacker can launch the job
template against arbitrary managed hosts using the job template's credentials,
resulting in privilege escalation and remote code execution on managed hosts. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The AWX_TASK_ENV setting accepts arbitrary environment variable
keys with no restriction, and its values are applied directly to the running
automation controller web and task processes rather than only to sandboxed
execution environments. A user with the system administrator role can set
variables such as REQUESTS_CA_BUNDLE, HTTPS_PROXY, SSLKEYLOGFILE, OPENSSL_CONF,
or LD_PRELOAD that reconfigure the control-plane process TLS trust store,
key-logging, OpenSSL engine, or dynamic linker. This enables silent interception
of the outbound TLS the control plane uses to fetch external secret-store
credentials and Red Hat subscription and Insights secrets, arbitrary file write
of TLS session keys, and potential native code execution in the control-plane
process, escalating an application administrator to compromise of the control
plane and all tenant secrets. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-controller.
When creating or editing an execution environment, the controller does not verify
that the requesting user has use permission on the container registry credential
referenced by the execution environment; it validates only the organization and
the credential kind. An authenticated user who is an execution-environment admin
of one organization can associate a container registry credential belonging to a
different organization -- one they cannot otherwise read, list, or use -- to an
execution environment they control. When a job runs with that execution
environment, the controller decrypts the foreign credential's registry password
and supplies it to the container runtime, disclosing another organization's
registry credentials across the tenant boundary. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-controller.
The execute-permission check on a workflow job template node's unified job
template is skipped when the node's currently stored unified job template is
empty: the check inspects only the existing value, not the incoming one, and a
node can be created without a unified job template. An authenticated user who
holds admin permission on a single workflow job template can create an empty node
and then patch it to reference any job template, project, inventory source,
system job, or workflow on the platform -- including ones in other organizations
that they cannot otherwise read or launch. Running their own workflow then
executes the victim template with the victim's attached credentials, inventory
and project, resulting in cross-organization privilege escalation to arbitrary
automation execution. The patch response also discloses the victim template's
name and description. |
| A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The Thycotic Secret Server external credential plugin passes a
user-supplied server URL to its SDK without validating the scheme, host, or IP
range, and the plugin backend is executed synchronously within the automation
controller web process. Using the external credential test endpoint, a user who
holds only the use role on such a credential can override the stored server URL
with an arbitrary internal address, causing the control plane to issue requests
to internal services. Although the response is a generic error, response timing
reveals whether internal hosts and ports are reachable, enabling internal
network reconnaissance and a blind request-forgery primitive from the control
plane, and each request can hold a web worker, affecting availability. |