A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute and item traversal on its arguments, an administrator can craft a template that walks from the user object into the application settings and reads the Django secret key and the database password. The formatted message is written to a logger that can be forwarded to an external log aggregator, whose destination is also administrator-controlled, allowing the secrets to be sent off the host. An authenticated administrator can thereby obtain the master encryption key used to protect all stored credentials and the database service password, enabling offline decryption of every stored credential, forgery of user sessions, and direct access to the controller database.
CVSS Details
- CVSS 3.1 Base Score: 8.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade python3.12-django-ansible-base+feature_flagsUpgrade automation-eda-controller-event-stream-servicesUpgrade automation-gateway-proxy-serverUpgrade automation-eda-controllerUpgrade receptor-debugsourceUpgrade aap-metrics-utilityUpgrade automation-controller-serverUpgrade python3.12-django-ansible-base+channel_authUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade automation-gateway-proxy-debugsourceUpgrade python3.12-django-ansible-base+rest_filtersUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade python3.12-galaxy-ngUpgrade automation-gateway-proxy-server-debuginfoUpgrade automation-gateway-serverUpgrade automation-controllerUpgrade automation-platform-uiUpgrade python3.12-django-ansible-baseUpgrade automation-controller-cliUpgrade python3.12-django-ansible-base+resource_registryUpgrade automation-gateway-configUpgrade automation-controller-venv-towerUpgrade automation-gateway-proxyUpgrade python3.12-django-ansible-base+api_documentationUpgrade automation-gatewayUpgrade python3.12-gitpythonUpgrade python3.12-django-ansible-base+authenticationUpgrade receptorctlUpgrade automation-eda-controller-worker-servicesUpgrade automation-eda-controller-baseUpgrade automation-controller-uiUpgrade python3.12-django-ansible-base+rbacUpgrade python3.12-django-ansible-base+activitystreamUpgrade python3-sqlparseUpgrade receptor-debuginfoUpgrade python3.12-sqlparseUpgrade python3.12-django-ansible-base+redis_clientUpgrade automation-hubUpgrade receptorUpgrade automation-eda-controller-base-services | Sep 25, 2026 | Sep 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub