An improper authorization flaw exists in the Ansible...
Moderate severity
Unreviewed
Published
Sep 12, 2024
to the GitHub Advisory Database
•
Updated Sep 12, 2024
Description
Published by the National Vulnerability Database
Sep 12, 2024
Published to the GitHub Advisory Database
Sep 12, 2024
Last updated
Sep 12, 2024
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via
automountServiceAccountToken: true
, resulting in privilege escalation to a service account.References