CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.6. See the original NVD description below for full technical details.
CVE
CVE-2024-6840
Severity
MEDIUM
CVSS
6.6
EPSS
0.43%
Original NVD Description
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege escalation to a service account.