Impact
A format‑string vulnerability exists in Red Hat Ansible Automation Platform 2’s automation‑controller. The administrator‑controlled template used for logging API 4xx errors is rendered against a live user object, allowing attribute traversal into application settings. This permits an administrator to extract the Django secret key and database password from the formatted log message, which can then be forwarded to an external log aggregator. The compromise reveals the master encryption key protecting stored credentials and the database password, enabling offline decryption of all stored secrets, session forgery, and direct database access.
Affected Systems
The vulnerability affects Red Hat Ansible Automation Platform 2, specifically the automation‑controller component. All instances running this product where the API error‑log template is administrator‑configurable are potentially impacted.
Risk and Exploitability
The CVSS score is 8.7, indicating high severity. The EPSS score is not available, so no quantitative exploitation probability can be reported. The vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated administrator; no additional privileges are needed beyond administrative rights. Once exploited, the attacker can exfiltrate secrets via the configured log aggregator or store them locally, giving full access to credential storage and the database.
OpenCVE Enrichment