A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in prevent_search() and is therefore accepted for arbitrary field lookups by the REST filter backend, even though it is omitted from the API serializer. Because the column is persisted before Ansible's no_log masking is applied, a user with only read access to a workflow — or, via a regular-expression lookup that bypasses the JSON cross-relation filter guard through the world-readable credential-types endpoint, any authenticated user with no roles — can use the result count as a boolean/count oracle to recover, character by character, secret values that a playbook author explicitly marked no_log, including across organizations.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade python3.12-django-ansible-baseUpgrade automation-gateway-configUpgrade receptorUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade automation-controller-serverUpgrade python3.12-django-ansible-base+channel_authUpgrade automation-controller-cliUpgrade python3.12-django-ansible-base+rbacUpgrade automation-gateway-proxyUpgrade automation-eda-controller-base-servicesUpgrade receptor-debuginfoUpgrade automation-eda-controller-event-stream-servicesUpgrade python3.12-django-ansible-base+resource_registryUpgrade automation-controller-venv-towerUpgrade python3-sqlparseUpgrade automation-gateway-proxy-serverUpgrade python3.12-django-ansible-base+feature_flagsUpgrade python3.12-django-ansible-base+api_documentationUpgrade automation-platform-uiUpgrade python3.12-django-ansible-base+redis_clientUpgrade automation-eda-controllerUpgrade automation-gateway-proxy-server-debuginfoUpgrade python3.12-sqlparseUpgrade aap-metrics-utilityUpgrade automation-hubUpgrade automation-gateway-serverUpgrade python3.12-django-ansible-base+rest_filtersUpgrade automation-eda-controller-worker-servicesUpgrade automation-controller-uiUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade python3.12-django-ansible-base+authenticationUpgrade automation-gatewayUpgrade python3.12-galaxy-ngUpgrade automation-controllerUpgrade automation-gateway-proxy-debugsourceUpgrade python3.12-gitpythonUpgrade receptor-debugsourceUpgrade python3.12-django-ansible-base+activitystreamUpgrade automation-eda-controller-baseUpgrade receptorctl | Sep 25, 2026 | Sep 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub