An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege escalation to a service account.
References
Configurations
No configuration.
History
12 Sep 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-12 17:15
Updated : 2024-09-12 18:14
NVD link : CVE-2024-6840
Mitre link : CVE-2024-6840
CVE.ORG link : CVE-2024-6840
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization