Impact
The vulnerability lies in the AWX component of Red Hat Ansible Automation Platform 2, where the pod_spec_override field in container groups implements an incomplete blocklist that permits injection of initContainers, serviceAccountName overrides, and projected service account token volumes. This flaw allows an attacker who gains administrator access to the AAP platform to craft malicious pod specifications that execute with elevated privileges, effectively escalating to OpenShift namespace‑level authority and enabling exfiltration of secrets stored in that namespace. The weakness is identified as CWE‑184.
Affected Systems
Red Hat Ansible Automation Platform 2 is affected. All installations of AAP 2 that expose the AWX web interface or API with the pod_spec_override functionality active are vulnerable; no specific minor version ranges are listed, so the entire product line 2 requires scrutiny.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity, and the EPSS score is not available, implying no publicly held data on exploitation frequency but still warranting concern. The vulnerability is not listed in CISA KEV, but its high score and direct impact on OpenShift namespaces suggest a significant risk if exploited. The likely attack vector is an account with AAP administrative privileges that submits a pod specification containing malicious overrides. Once injected, the attacker can gain namespace‑level access and read or export secrets, compromising confidentiality and potentially enabling further lateral movement within the cluster.
OpenCVE Enrichment