Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in Red Hat Ansible Automation Platform's automation controller. This flaw allows an attacker with minimal privileges to potentially execute arbitrary code on managed systems by exploiting a credential exposure and manipulating network headers. The main concern is confirming relevance and exposure given the platform's role in managing critical infrastructure.
- A secret can be read by low-privilege users.
- Attackers can gain remote control of systems.
- Assess exposure of Ansible Automation Platform.
Attack Path
How an attacker could exploit the issue
An attacker with read-only access to job templates can uncover a secret used for provisioning callbacks. By then manipulating the gateway's header, they can trick the system into believing the request originates from a managed host. This allows them to launch jobs against arbitrary hosts, leading to unauthorized execution of commands.
- Requires minimal user access.
- Spoofed header triggers callback.
- Leads to code execution on hosts.
Live Threat
Current exploitation, exposure, and threat context
A flaw in Red Hat Ansible Automation Platform's automation-controller could allow a minimally privileged user to access a sensitive secret. When the controller is deployed behind the AAP gateway with an empty proxy allow-list, an attacker could potentially read this secret and then spoof the X-Forwarded-For header to impersonate a host within the job template's inventory. This could lead to the attacker launching job templates against arbitrary managed hosts using the job template's credentials, potentially resulting in privilege escalation and remote code execution on those hosts.
- Secret and job template credentials at risk.
- Attacker spoofs X-Forwarded-For header.
- Privilege escalation and code execution possible.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical vulnerability impacts Red Hat Ansible Automation Platform's automation-controller. Responsibility for remediation likely falls to the platform or infrastructure teams, in coordination with security teams. The first practical step is to identify all instances of the affected platform, determine their exposure and business criticality, and locate the accountable owner to plan mitigation.
- Platform or infrastructure teams own the issue.
- Verify affected controller accessibility and criticality.
- Plan remediation based on exposure and impact.