SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2024-6840

An improper authorization flaw exists in the Ansible Automation Controller.

MEDIUM 6.6EPSS 0.43%

Does this matter?

Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.

Description

An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege escalation to a service account.

CVSS 3.1
6.6 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
EPSS
0.43% probability · 36th percentile
CISA KEV
Not listed
Weakness
CWE-285
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.