PT-2024-37897 · Ansible · Ansible Automation Controller

Robb Gatica

·

Published

2024-02-09

·

Updated

2024-09-12

·

CVE-2024-6840

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ansible Automation Controller (affected versions not specified)
Description An improper authorization flaw exists in the Ansible Automation Controller, allowing an attacker using the k8S API server to send an HTTP request with a service account token mounted via automountServiceAccountToken: true, resulting in privilege escalation to a service account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-6840
RHSA-2024:6428

Affected Products

Ansible Automation Controller