Red Hat Ansible Automation Platform 2.6 Container Release Update
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
A command injection vulnerability was found in galaxyng. The dogitcheckout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. An authenticated user who controls a git repository can create a branch or tag with shell metacharacters in the name to achieve remote code execution on the pulp worker. The vulnerable endpoint is only reachable when GALAXYENABLELEGACYROLES is set to True, which is not the default configuration.
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the nolog feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.4 Container Release Update
Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.5 Container Release Update
Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform Execution Environments Container Release Update
Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform Execution Environments Container Release Update
Important: Red Hat Ansible Automation Platform Execution Environments Container Release Update
Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.4 Container Release Update
Important: Red Hat Ansible Automation Platform 2.5 Container Release Update
Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.5 Container Release Update
Important: Red Hat Ansible Automation Platform 2.4 Container Release Update
AAP 2.6 introduced a user auto-link strategy that automatically links an external IDP identity to an existing AAP user account when the IDP-provided email matches a user's email. The system performs no verification that the email is actually proven to belong to the authenticating user, and the behavior is hard-coded with no admin toggle. This creates two primary exploitable attack paths: (1) a regular AAP user can pre-position their account to pre-hijack a victim's first IDP login; (2) an attacker who can set an arbitrary email on a configured IDP can link to any existing AAP account, including admin accounts.
Red Hat Ansible Automation Platform 2.6 Container Release Update
Important: Red Hat Ansible Automation Platform 2.3 Product Security and Bug Fix Update
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the testheaders field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container.
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. A malicious user could use it to perform actions to impact users by using the "?next=" in a URL and hence redirecting, injecting malicious script, stealing session and data.
A flaw was found in Ansible where the secret information present in asyncfiles are getting disclosed when the user changes the jobdir to a world readable directory. Any secret information in an async status file will be readable by a malicious user on that system. This flaw affects Ansible Tower 3.7 and Ansible Automation Platform 1.2.
A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.