CVE-2024-6840: Automation-controller: gain access to the k8s api server via job execution with container group
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege escalation to a service account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6840?
CVE-2024-6840 is classified as a critical vulnerability due to its potential for privilege escalation in the Ansible Automation Controller.
How do I fix CVE-2024-6840?
To mitigate CVE-2024-6840, ensure that service account tokens are not automatically mounted by configuring `automountServiceAccountToken: false`.
Who is affected by CVE-2024-6840?
CVE-2024-6840 affects users of the Ansible Automation Controller that utilize Kubernetes API servers with certain configurations.
What type of vulnerability is CVE-2024-6840?
CVE-2024-6840 is an improper authorization flaw that allows for privilege escalation.
What is the potential impact of CVE-2024-6840?
The potential impact of CVE-2024-6840 includes unauthorized access and control over sensitive resources within the Ansible Automation Controller.