A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container.
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language.For details about this release, refer to the release notes listed in the References section.
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language.For details about this release, refer to the release notes listed in the References section.
Red Hat Ansible Automation Platform 2.6 Container Release Update
A command injection vulnerability was found in galaxyng. The dogitcheckout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. An authenticated user who controls a git repository can create a branch or tag with shell metacharacters in the name to achieve remote code execution on the pulp worker. The vulnerable endpoint is only reachable when GALAXYENABLELEGACYROLES is set to True, which is not the default configuration.
A command injection vulnerability was found in galaxyng's legacy role import functionality. The dogitcheckout() function in galaxyng/app/api/v1/tasks.py constructs shell commands via f-string interpolation using unsanitized git ref names (branch/tag names from the githubreference parameter) and executes them with subprocess.run(cmd, shell=True). An authenticated user who controls a git repository can create a branch or tag with shell metacharacters (such as ;, |, $(), &, >) in the name, and when the legacy role import processes this reference, the shell metacharacters are interpreted by the shell, achieving remote code execution on the pulp worker process.
The vulnerability requires GALAXYENABLELEGACYROLES to be set to True, which is NOT the default configuration in any shipped version of Red Hat Ansible Automation Platform (2.4 through 2.6). When this setting is False (the default), the v1 API routes are not registered in Django URL routing and the vulnerable endpoint returns 404. However, any deployment that explicitly enables legacy role support (e.g., community-galaxy profile or custom configurations) is exposed to authenticated RCE.
A secondary vector exists via the alternatecloneurl parameter, which accepts arbitrary URLs with no validation (enabling SSRF), though the git clone operation on that path uses shell=False, preventing shell injection via that specific parameter.
Red Hat Ansible Automation Platform 2.6 Container Release Update
A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.
AAP 2.6 introduced a user auto-link strategy that automatically links an external IDP identity to an existing AAP user account when the IDP-provided email matches a user's email. The system performs no verification that the email is actually proven to belong to the authenticating user, and the behavior is hard-coded with no admin toggle. This creates two primary exploitable attack paths: (1) a regular AAP user can pre-position their account to pre-hijack a victim's first IDP login; (2) an attacker who can set an arbitrary email on a configured IDP can link to any existing AAP account, including admin accounts.
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the testheaders field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. A malicious user could use it to perform actions to impact users by using the "?next=" in a URL and hence redirecting, injecting malicious script, stealing session and data.
Important: Red Hat Ansible Automation Platform 2.4 Container Release Update
Important: Red Hat Ansible Automation Platform 2.5 Container Release Update
Moderate: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.5 Container Release Update
Important: Red Hat Ansible Automation Platform 2.4 Container Release Update
Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform Execution Environments Container Release Update
Important: Red Hat Ansible Automation Platform Execution Environments Container Release Update
Moderate: Red Hat Ansible Automation Platform 2.5 Container Release Update
Important: Red Hat Ansible Automation Platform Execution Environments Container Release Update
Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.5 Container Release Update
Moderate: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update