Impact
A flaw in the Ansible Automation Platform 2 automation controller allows privileged users to inject arbitrary rsyslog RainerScript directives into the control-plane configuration file. By manipulating the LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH, and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE settings, an attacker can execute an omprog action that runs commands inside the rsyslog process. This injection can expose the controller SECRET_KEY, decrypt stored credentials, and fully compromise the control plane.
Affected Systems
Red Hat Ansible Automation Platform 2 is affected. No specific sub‑version information is provided, but any deployment of version 2 that has not applied the vendor fix is vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack requires privileged (superuser) access to the controller; once achieved, the attacker can obtain full control of the control plane. The available information suggests the exploit is straightforward on affected systems, underscoring the importance of timely remediation.
OpenCVE Enrichment