CyberRota Analysis
AI-GeneratedA vulnerability in the Red Hat Ansible Automation Platform's automation-controller allows a user with the JobTemplate Admin role to exploit revalidation of survey questions of type password, revealing stored passwords in plaintext through error messages. This flaw poses a significant risk as it enables unauthorized access to sensitive credentials, potentially compromising workflows and automation processes. Organizations utilizing this platform should prioritize addressing this vulnerability to safeguard their automation environments and protect sensitive information.
Original NVD Description
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller decrypts the stored password and includes its plaintext value in the minimum/maximum length validation error message returned in the HTTP response. A user with the delegated JobTemplate Admin role can tighten the survey length constraint and trigger revalidation of a schedule or node created by another, higher-privileged user, thereby recovering that user's stored password in plaintext.