REDHAT-BUG-2527090: Medium severity Ansible automation-controller (AWX) vulnerability
A flaw was found in automation-controller (AWX). Write-only survey password values stored on Schedules and WorkflowJobTemplateNodes are encrypted at rest and masked as $encrypted$ on read. LaunchConfigurationBaseSerializer.validate (awx/api/serializers.py) replaces an incoming $encrypted$ with the stored DB ciphertext and revalidates prompts against the job template's current surveyspec; SurveyJobTemplateMixin.acceptorignorevariables (awx/main/models/mixins.py) decrypts the stored password before validation, and surveyelementvalidation interpolates the decrypted plaintext into the "value ... is too small/too large" min/max error for text/textarea/password questions. The error dict is returned verbatim as the HTTP 400 body. A user holding only the delegated JobTemplate Admin role can POST a tightened surveyspec (e.g. "max":1) and then PATCH a schedule of that job template -- either echoing $encrypted$ for the variable, or simply re-stating unifiedjobtemplate to force full-prompt revalidation without knowing the variable name (serializers.py forces full revalidation when unifiedjobtemplate is present) -- and read the stored plaintext password of a schedule created by a different, higher-privileged user (ScheduleAccess.canchange grants a JT admin write on all schedules of the template regardless of creator). The same base serializer backs WorkflowJobTemplateNodeSerializer, so workflow nodes are equally affected. Discovered internally; verified live on AAP 2.7 / automation-controller 4.8.1; still present on devel. Upstream: github.com/ansible/awx (api/serializers.py LaunchConfigurationBaseSerializer; main/models/mixins.py surveyelementvalidation / acceptorignorevariables; main/access.py ScheduleAccess.canchange)
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attacker needs the delegated JobTemplate Admin role. They must be able to modify the job template survey specification and PATCH a schedule associated with that job template.
Which stored secrets can be exposed?
The affected values are write-only survey password values stored on Schedules and WorkflowJobTemplateNodes. The plaintext can be returned in an HTTP 400 validation error when the stored value fails a tightened minimum or maximum validation constraint.
Does the attacker need to know the password variable name or its current value?
No. They can echo the masked "$encrypted$" value, or re-state unified_job_template to force full prompt revalidation without knowing the variable name. The server retrieves and decrypts the stored value during validation.
How is the secret disclosed to the attacker?
The decrypted plaintext is interpolated into a survey validation error such as a value being too small or too large. That error dictionary is returned verbatim in the HTTP 400 response body.