Impact
The event consumer in AWX performs RBAC checks only for certain event groups. Three event groups—inventory_update_events, project_update_events, and system_job_events—are not checked. As a result, any authenticated user may subscribe to these streams for any object ID and receive real‑time stdout from jobs in organizations the user should not access. This allows cross‑organization disclosure of potentially sensitive output. The flaw is a missing authorization check (CWE‑862).
Affected Systems
The vulnerability is present in Red Hat Ansible Automation Platform 2. Users running the AWX/Controller component of this platform are vulnerable. No other product versions are listed.
Risk and Exploitability
Based on the CVSS score of 6.5 the risk is classified as medium. The EPSS score of < 1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA KEV. Attackers only need to be authenticated; the flaw does not require privileged roles. Any logged‑in user could subscribe via the websocket interface and obtain confidential stdout data, with no special environmental conditions beyond normal authentication and websocket access.
OpenCVE Enrichment