CyberRota Analysis
AI-GeneratedA critical vulnerability exists in the Red Hat Ansible Automation Platform's automation-controller, where the provisioning-callback secret is exposed to users with minimal permissions, allowing them to access sensitive information. Additionally, the reliance on the X-Forwarded-For header for host identification can be exploited by an attacker to execute job templates against arbitrary managed hosts, leading to privilege escalation and potential remote code execution. Organizations using this platform should prioritize immediate remediation to mitigate the risk of unauthorized access and system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback endpoint trusts a client-supplied X-Forwarded-For header to determine the calling host when the controller is deployed behind the AAP gateway with an empty proxy allow-list. By reading the secret and spoofing X-Forwarded-For to match any host in the job template's inventory, a minimally privileged or unauthenticated remote attacker can launch the job template against arbitrary managed hosts using the job template's credentials, resulting in privilege escalation and remote code execution on managed hosts.