CVE-2024-9620
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-9620 is a newly identified vulnerability in Ansible Automation Platform's Event-Driven Automation (EDA) feature. This issue stems from the lack of encryption for sensitive information transmitted and stored between EDA and the platform. An attacker with network access can exploit this vulnerability by intercepting plaintext data transmissions, while an attacker with system access can gain unauthorized access to plaintext data in the EDA and AAP databases. These actions could potentially lead to unintended data disclosure or unauthorized system access. Organizations using Ansible Automation Platform are advised to apply appropriate patches or safeguards to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Red Hat Ansible Automation Platform
Affected Vendors
- Red Hat