CyberRota Analysis
AI-GeneratedA vulnerability exists in the input-validation mechanism of the automation controller, specifically within the sanitize_jinja() function, which inadequately filters user-supplied Jinja expressions. This flaw allows low-privileged users to inject malicious Jinja code, potentially executing arbitrary commands and disclosing sensitive credential information in the execution environment. Organizations utilizing this automation controller should prioritize patching this vulnerability to mitigate risks associated with unauthorized command execution and credential exposure.
Original NVD Description
A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first interior '}' or '%' character, so a Jinja expression containing an inner brace (for example an empty dict) is accepted while remaining valid Jinja. Because sanitize_jinja() is the sole guard on several launch-time fields — ad-hoc command module_args, Machine-credential username / become_method / become_user, and inventory host names — a low-privileged user can inject Jinja that ansible-core evaluates in the execution environment. This enables execution of arbitrary commands in the execution environment (bypassing an administrator's AD_HOC_COMMANDS module allowlist) and disclosure of secrets belonging to credentials the attacker cannot read (by templating a co-attached credential's injected environment variables), across the credential access-control boundary.