Impact
The vulnerability arises from copying clear‑text notification recipients into an unprotected response field when notifications are sent, while the NotificationTemplate configuration is protected from API filtering. An authenticated user of the system can issue a relational filter that traverses object associations without per‑hop authorization, effectively turning the endpoint into a boolean oracle. By repeatedly querying the filter, an attacker can recover the recipient values of other tenants’ notifications, which may contain PagerDuty service keys, Slack, Mattermost, RocketChat, or webhook bearer‑token URLs. The flaw results in confidentiality loss for external service credentials and is classified as CWE‑639.
Affected Systems
Red Hat Ansible Automation Platform 2 is affected. No specific version subrange is published, so any installation of Platform 2 is considered vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity. The EPSS score is not available, so the current probability of exploitation is unknown, but the flaw is exploitable by any authenticated user without elevated privileges, making it readily actionable in a multitenant environment. The vulnerability is not listed in CISA’s KEV catalog, yet given the scope across organizations, an attacker could compromise multiple tenants’ secrets. The likely attack vector is an authenticated consumer of the Credential‑Types API using a crafted relational filter as a boolean oracle. If unmitigated, this can lead to widespread leakage of critical integration keys and tokens.
OpenCVE Enrichment