Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in Red Hat Ansible Automation Platform's automation controller that could allow unauthorized command execution. Specifically, a flaw in how project URLs are handled enables an attacker with project modification permissions to run arbitrary commands on the control-plane task pod. This could lead to broader compromise within the cluster, impacting multiple tenants. The primary concern is to confirm if your Ansible Automation Platform is affected and to what extent.
- Flaw allows attackers to run commands on the Ansible controller.
- Remote code execution can lead to cross-tenant compromise.
- Assess relevance and exposure for Ansible Automation Platform.
Attack Path
How an attacker could exploit the issue
An attacker with the ability to create or modify projects could exploit this vulnerability. By crafting a malicious project URL, an attacker can trick the system into executing arbitrary commands on the control-plane task pod. This leads to potential command execution, data compromise, and unauthorized lateral movement within the cluster.
- Network access required; authenticated user.
- Malicious project URL triggers command execution.
- Arbitrary code execution and lateral movement.
Live Threat
Current exploitation, exposure, and threat context
When supported, a user with project creation privileges could execute arbitrary commands on the control-plane task pod by providing a specially crafted git project URL. This could lead to cross-tenant compromise and lateral movement within the cluster.
- Control-plane task pod command execution.
- Specially crafted project URL input.
- In-cluster lateral movement.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Ansible Automation Platform team is likely responsible for this issue, with support from infrastructure or platform teams for deployment. The first practical step is to identify all instances of the automation controller, assess their exposure and criticality, and locate the accountable owner for each. Remediation planning should then be prioritized based on these findings.
- Ansible Automation Platform team owns the issue.
- Verify controller instance exposure and criticality.
- Plan remediation based on assessed risk.