A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacker-controlled) header value. As a result, an attacker can forge the source IP address recorded for their requests in the Controller's audit and access logs, degrading the integrity of forensic and SIEM attribution. The flaw does not grant additional access.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade python3.12-django-ansible-base+channel_authUpgrade python3.12-gitpythonUpgrade python3.12-sqlparseUpgrade automation-eda-controllerUpgrade automation-gateway-proxy-serverUpgrade python3.12-django-ansible-base+authenticationUpgrade automation-eda-controller-worker-servicesUpgrade receptor-debugsourceUpgrade python3.12-django-ansible-base+rest_filtersUpgrade receptor-debuginfoUpgrade automation-controllerUpgrade automation-gateway-serverUpgrade automation-gateway-proxy-debugsourceUpgrade python3.12-django-ansible-base+rbacUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade automation-gateway-configUpgrade python3.12-galaxy-ngUpgrade automation-eda-controller-baseUpgrade automation-hubUpgrade automation-platform-uiUpgrade python3-sqlparseUpgrade python3.12-django-ansible-base+activitystreamUpgrade python3.12-django-ansible-base+redis_clientUpgrade python3.12-django-ansible-base+api_documentationUpgrade automation-gatewayUpgrade automation-controller-venv-towerUpgrade automation-gateway-proxy-server-debuginfoUpgrade automation-controller-serverUpgrade python3.12-django-ansible-base+feature_flagsUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade python3.12-django-ansible-base+resource_registryUpgrade receptorUpgrade automation-controller-uiUpgrade receptorctlUpgrade automation-eda-controller-base-servicesUpgrade python3.12-django-ansible-baseUpgrade aap-metrics-utilityUpgrade automation-eda-controller-event-stream-servicesUpgrade automation-gateway-proxyUpgrade automation-controller-cli | Sep 25, 2026 | Sep 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub