Impact
A vulnerability in the automation‑controller API’s public /api/v2/ping/ endpoint allows an unauthenticated attacker to receive an over‑serialized snapshot of the automation‑mesh, including node hostnames, types, UUIDs, heartbeats, capacities, exact versions, instance‑group names and membership, the deployment install UUID, and the active control node. This information exposure is limited to confidentiality; no secrets or credentials are revealed. The flaw is classified as CWE‑497, indicating that sensitive data is disclosed without proper authentication.
Affected Systems
Red Hat Ansible Automation Platform 2 is affected; all installed versions lack the fix as specific version details are not listed.
Risk and Exploitability
The CVSS score of 5.3 signals a moderate severity. EPSS is not available, so the current probability of exploitation is unknown. Because the vulnerability is remote and unauthenticated, an attacker could readily enumerate the control plane and fingerprint software versions, potentially aiding future targeted attacks. It is not present in the CISA Known Exploited Vulnerabilities catalog. The risk is primarily in information disclosure that could be used for reconnaissance.
OpenCVE Enrichment