CyberRota Analysis
AI-GeneratedThe vulnerability affects the POST method in the JobTemplate API of the affected products, which lacks proper object-level role-based access control (RBAC) checks, allowing unauthorized users to potentially copy sensitive JobTemplate configurations. This oversight could lead to unauthorized access to critical resources, as the system only verifies if the user can add or copy related objects without confirming read permissions on the source JobTemplate. Organizations using this API should prioritize remediation to prevent potential data exposure and ensure compliance with access control policies.
Original NVD Description
CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'read', obj) — but post() (lines 1001–1010) does not. POST only checks: can_access(model, 'add', create_kwargs_check) can_access(model, 'copy_related', obj) For JobTemplate, can_add (awx/awx/main/access.py:1465–1520) gates on inventory.use_role + project.use_role + execution_environment.read_role — resource-level roles that do not imply read on the source JT — and can_copy_related (1522–1534) checks only credentials.use_role. None of these imply the caller can read the source JT.