CVE-2024-9620

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Oct 10, 2024
CWE ID 319

Summary

CVE-2024-9620 is a newly identified vulnerability in Ansible Automation Platform's Event-Driven Automation (EDA) feature. This issue stems from the lack of encryption for sensitive information transmitted and stored between EDA and the platform. An attacker with network access can exploit this vulnerability by intercepting plaintext data transmissions, while an attacker with system access can gain unauthorized access to plaintext data in the EDA and AAP databases. These actions could potentially lead to unintended data disclosure or unauthorized system access. Organizations using Ansible Automation Platform are advised to apply appropriate patches or safeguards to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Red Hat Ansible Automation Platform

Affected Vendors

  • Red Hat