PT-2024-17021 · Red Hat · Ansible+1

Published

2024-11-20

·

Updated

2024-12-18

·

CVE-2024-11483

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ansible Automation Platform (AAP) (affected versions not specified) Ansible nan (affected versions not specified)
Description A vulnerability was found in the Ansible Automation Platform (AAP) and Ansible nan, allowing attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on ansible base.oauth2 provider for OAuth2 authentication. While the impact is limited to actions within the user’s assigned permissions, it undermines scoped access controls, potentially allowing unintended modifications in the application and consuming services.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-01646
CVE-2024-11483
RHSA-2024:11145

Affected Products

Ansible
Ansible Automation Platform