CVE-2024-9620 Information
Oct 09, 2024
cve
Description
A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP) which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transmitted between the EDA and AAP. An attacker with system access could exploit this vulnerability by reading the plaintext data stored in EDA and AAP databases.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://access.redhat.com/security/cve/CVE-2024-9620 https://bugzilla.redhat.com/show_bug.cgi?id=2317129
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: