CVE-2024-9620

MEDIUM

Ansible Automation Platform - Info Disclosure

Title source: llm
STIX 2.1

Description

A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transmitted between the EDA and AAP. An attacker with system access could exploit this vulnerability by reading the plaintext data stored in EDA and AAP databases.

Scores

CVSS v3 5.3
EPSS 0.0007
EPSS Percentile 21.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (1)
Red Hat/Red Hat Ansible Automation Platform 2
Published Oct 08, 2024
Tracked Since Feb 18, 2026