REDHAT-BUG-2317129: Medium severity ansible automation platform vulnerability
The Event-Driven Automation (EDA) in Ansible Automation Platform (AAP) in versions equal to or below 2.4 lacks encryption of sensitive information, such as ServiceNow's credentials on an integration. This vulnerability leaves sensitive data in plaintext, as the component does not use AAP's built-in encryption features like in AAP's Survey.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2317129?
The severity of REDHAT-BUG-2317129 is considered high due to the exposure of sensitive information.
How do I fix REDHAT-BUG-2317129?
To fix REDHAT-BUG-2317129, upgrade to a version of Ansible Automation Platform that is above 2.4.
What types of sensitive information are affected by REDHAT-BUG-2317129?
REDHAT-BUG-2317129 affects sensitive information such as ServiceNow's credentials.
Which versions of Ansible Automation Platform are affected by REDHAT-BUG-2317129?
Ansible Automation Platform versions equal to or below 2.4 are affected by REDHAT-BUG-2317129.
What impact does REDHAT-BUG-2317129 have on security?
REDHAT-BUG-2317129 can lead to unauthorized access to sensitive data stored in plaintext.