A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD, LD_LIBRARY_PATH, PYTHONSTARTUP and GIT_SSH_COMMAND. Combined with the credential file injector, a privileged user can write an attacker-controlled script into the execution environment and point BASH_ENV at it, obtaining arbitrary code execution inside the execution-environment container for any job that attaches a credential of that type.
CVSS Details
- CVSS 3.1 Base Score: 7.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade python3.12-django-ansible-base+oauth2_providerUpgrade automation-hubUpgrade automation-controller-cliUpgrade python3.12-django-ansible-base+channel_authUpgrade automation-gateway-configUpgrade automation-gateway-proxy-server-debuginfoUpgrade automation-controller-venv-towerUpgrade automation-controller-uiUpgrade python3.12-django-ansible-base+api_documentationUpgrade python3.12-django-ansible-base+resource_registryUpgrade automation-eda-controller-event-stream-servicesUpgrade receptorUpgrade python3.12-django-ansible-base+activitystreamUpgrade aap-metrics-utilityUpgrade python3.12-django-ansible-base+redis_clientUpgrade automation-eda-controllerUpgrade automation-controller-serverUpgrade automation-eda-controller-worker-servicesUpgrade python3.12-django-ansible-base+feature_flagsUpgrade receptor-debugsourceUpgrade python3.12-django-ansible-base+rbacUpgrade automation-gateway-serverUpgrade python3.12-django-ansible-baseUpgrade python3-sqlparseUpgrade automation-platform-uiUpgrade python3.12-gitpythonUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade python3.12-django-ansible-base+rest_filtersUpgrade automation-eda-controller-base-servicesUpgrade receptorctlUpgrade automation-gateway-proxy-debugsourceUpgrade automation-gateway-proxyUpgrade python3.12-django-ansible-base+authenticationUpgrade automation-eda-controller-baseUpgrade python3.12-sqlparseUpgrade receptor-debuginfoUpgrade automation-gateway-proxy-serverUpgrade python3.12-galaxy-ngUpgrade automation-gatewayUpgrade automation-controller | Sep 25, 2026 | Sep 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub