CVE-2024-6840 Information
Sep 13, 2024
cve
Description
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via automountServiceAccountToken: true resulting in privilege escalation to a service account.
Reference
https://access.redhat.com/errata/RHSA-2024:6428 https://access.redhat.com/security/cve/CVE-2024-6840 https://bugzilla.redhat.com/show_bug.cgi?id=2298492
Share on: