CyberRota Analysis
AI-GeneratedA vulnerability in the Ansible Automation Platform's automation-controller allows a privileged user to exploit the custom Credential Type environment-variable injector, which inadequately validates variable names against a deny-list. This oversight enables the injection of malicious scripts into the execution environment, potentially leading to arbitrary code execution within the container for any job using the compromised credential. Organizations utilizing Ansible Automation Platform should prioritize addressing this issue to mitigate the risk of unauthorized code execution and potential system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, PYTHONSTARTUP and GIT_SSH_COMMAND. Combined with the credential file injector, a privileged user can write an attacker-controlled script into the execution environment and point BASH_ENV at it, obtaining arbitrary code execution inside the execution-environment container for any job that attaches a credential of that type.