REDHAT-BUG-2458142: High severity Red Hat Ansible Automation Platform vulnerability
AAP 2.6 introduced a user auto-link strategy that automatically links an external IDP identity to an existing AAP user account when the IDP-provided email matches a user's email. The system performs no verification that the email is actually proven to belong to the authenticating user, and the behavior is hard-coded with no admin toggle. This creates two primary exploitable attack paths: (1) a regular AAP user can pre-position their account to pre-hijack a victim's first IDP login; (2) an attacker who can set an arbitrary email on a configured IDP can link to any existing AAP account, including admin accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2458142?
The severity of REDHAT-BUG-2458142 is classified as high due to the risks associated with unauthorized account access.
How do I fix REDHAT-BUG-2458142?
To fix REDHAT-BUG-2458142, update your Red Hat Ansible Automation Platform to the latest patched version provided by Red Hat.
What are the implications of REDHAT-BUG-2458142?
The implications of REDHAT-BUG-2458142 include potential unauthorized access to user accounts if an attacker can spoof an IDP email.
Who is affected by REDHAT-BUG-2458142?
Users of Red Hat Ansible Automation Platform version 2.6 are affected by REDHAT-BUG-2458142.
Is there a workaround for REDHAT-BUG-2458142?
A temporary workaround for REDHAT-BUG-2458142 is to disable the auto-link feature until a fix can be applied.