CVE Vulnerabilities

CVE-2024-1657

Cleartext Transmission of Sensitive Information

Published: Apr 25, 2024 | Modified: Feb 25, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Ansible Automation Platform 2.4 for RHEL 8RedHatansible-automation-platform-installer-0:2.4-6.el8ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 8RedHatansible-rulebook-0:1.0.5-1.el8ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 8RedHatautomation-eda-controller-0:1.0.5-1.el8ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 9RedHatansible-automation-platform-installer-0:2.4-6.el9ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 9RedHatansible-rulebook-0:1.0.5-1.el9ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 9RedHatautomation-eda-controller-0:1.0.5-1.el9ap*

Potential Mitigations

References