REDHAT-BUG-2527187: High severity Ansible automation-controller vulnerability
A flaw was found in Ansible Automation Platform's automation-controller. Custom Credential Types let an author define injectors.env (environment variables set in the execution environment when a credential of that type is attached to a job) and injectors.file (files rendered into the execution environment whose path is exposed to other injectors as {{ tower.filename }}). The env-variable names are validated only by a deny-list: CredentialTypeInjectorField.validateenvvarallowed (awx/main/fields.py:689-701) rejects names beginning with "ANSIBLE" and names present in the ENVBLOCKLIST frozenset (awx/main/constants.py:48-70). The stated purpose of this control is to stop injectors from hijacking the runner process (it blocks PATH, PYTHONPATH, VIRTUALENV and all ANSIBLE configuration variables). The deny-list is incomplete: it does not include BASHENV, ENV, LDPRELOAD, LDLIBRARYPATH, LDAUDIT, PYTHONSTARTUP, PYTHONWARNINGS, GITSSHCOMMAND, PERL5OPT, or similar loader/ process-hijacking variables, so those names pass validation. An attacker can therefore define a credential type whose file injector writes a shell script and whose env injector sets BASHENV to {{ tower.filename }}. Every non-interactive bash process spawned during a job (Ansible modules shell out constantly) then sources and executes the attacker's script, yielding arbitrary code execution inside the execution-environment container — independent of the playbook content — for any job that attaches a credential of the malicious type, with access to the secrets of all co-attached credentials in the same job environment and to any inventory host the job can reach. The same weak check is repeated at the runtime injection sink (awxplugins.interfaces temporaryprivateinjectapi.py, which re-checks only ENVBLOCKLIST), so the fix must be applied in both places. Creating a custom credential type requires Controller superuser (CredentialTypeAccess inherits BaseAccess), so this is primarily a defense-in-depth bypass of a control whose explicit purpose is to constrain exactly this behavior; however, an organization-level Credential Admin (not a superuser) can weaponize an already-existing malicious custom type, and in Gateway-managed AAP 2.5+ the platform-admin role is explicitly not host/EE root, so code execution in the execution environment via a configuration API crosses a real trust boundary.
Upstream: https://github.com/ansible/tower (private) / awxplugins.interfaces Affected files: awx/main/fields.py:689-701; awx/main/constants.py:48-70; awxplugins/interfaces/temporaryprivateinjectapi.py:263-288
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Extend the deny-list to reject BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, LD_AUDIT, PYTHONSTARTUP, PYTHONWARNINGS, GIT_SSH_COMMAND, and PERL5OPT, and apply the same validation at both awx/main/fields.py:689-701 and awx_plugins/interfaces/_temporary_private_inject_api.py:263-288.
Ansible Automation Platform automation-controller ENV_BLOCKLIST = BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, LD_AUDIT, PYTHONSTARTUP, PYTHONWARNINGS, GIT_SSH_COMMAND, PERL5OPT
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments are exposed where Custom Credential Types can define environment-variable and file injectors and credentials of those types are attached to jobs. The affected validation allows certain process- and loader-related environment variable names that are not in the deny-list.
What capabilities does an attacker need?
An attacker needs the ability to define a Custom Credential Type with injectors. The described technique uses a file injector to write a shell script and an environment injector to set BASH_ENV to the rendered file path.
How can administrators look for potentially malicious credential types?
Review Custom Credential Types for environment injectors using names not blocked by the deny-list, particularly BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, LD_AUDIT, PYTHONSTARTUP, PYTHONWARNINGS, GIT_SSH_COMMAND, and PERL5OPT. Give particular attention to types that combine those environment injectors with file injectors.