Ansible Automation Platform vulnerability
CVE-2024-9620

5.3MEDIUM

Key Information:

Vendor
Red Hat
Vendor
CVE Published:
8 October 2024

Summary

A critical flaw exists in the Event-Driven Automation (EDA) component of the Ansible Automation Platform, whereby sensitive information is transmitted and stored without encryption. This vulnerability exposes plaintext data to attackers with network access, who could intercept unprotected communications between the EDA and AAP. Additionally, attackers with system access could gain access to sensitive information stored in the EDA and AAP databases, further compromising data integrity. Organizations leveraging this platform should take immediate steps to mitigate the risk associated with this vulnerability to safeguard their sensitive information.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Enzo Ferreira (Red Hat).
.