CVE-2024-6840

CVSS V2 None CVSS V3 None
Description
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege escalation to a service account.
Overview
  • CVE ID
  • CVE-2024-6840
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-09-12T16:35:08.921Z
  • Last Modified Date
  • 2024-09-12T16:54:33.670Z
References
Reference URL Reference Tags
https://access.redhat.com/errata/RHSA-2024:6428 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/security/cve/CVE-2024-6840 vdb-entry x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=2298492 issue-tracking x_refsource_REDHAT
History
Created Old Value New Value Data Type Notes
2024-09-13 13:13:12 Added to TrackCVE