Impact
A flaw in the Ansible Automation Platform’s automation‑controller causes it to trust the client‑supplied X‑Forwarded‑For header as the request’s client IP without verifying its origin. The controller accepts the leftmost value from the header, allowing an attacker who can send HTTP requests to the controller to forge the source IP recorded in audit and access logs. This results in degraded integrity of forensic and SIEM attribution data. The vulnerability does not provide additional access or privileges; it merely corrupts the audit trail.
Affected Systems
The vulnerability affects Red Hat Ansible Automation Platform 2. All sub‑versions shipped with the default production configuration that unconditionally trusts X‑Forwarded‑For are susceptible. The flaw is present in the cpe:2.3:a:redhat:ansible_automation_platform:2 component.
Risk and Exploitability
The CVSS score of 4.3 indicates low to moderate severity. Because no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of widespread exploitation is currently considered low. Nevertheless, the issue can be triggered remotely by any entity that can make HTTP requests to the controller, and it may be used for covert logging or misattribution. The attacker does not gain additional control or permissions on the system.
OpenCVE Enrichment