Database/Control plane, storage & DevOps
Ansible automation-controller: survey length-validation error leaks a stored password in plaintext
Impact
Survey answers of type password are stored encrypted and shown only as a placeholder, but when a schedule or workflow job template node is revalidated against a tightened survey spec, automation-controller decrypts the stored value and includes it verbatim in the min/max-length validation error returned in the HTTP response. A user holding only the delegated JobTemplate Admin role can tighten the length constraint and force revalidation of a schedule created by a more privileged user, reading back that user's secret. In a datacenter that drives fleet provisioning, BMC and firmware workflows through AAP, those survey passwords are commonly BMC, switch, registry or cloud credentials - so this is a privilege-escalation path from template admin to whatever the fleet automation can reach. Confidentiality only; nothing is modified.
Who can reach it
Authenticated over the network to the automation-controller API or UI, holding the delegated JobTemplate Admin role on a template whose survey another user answered. No host access needed.
What to do
Apply the Red Hat errata for your AAP stream (RHSA-2026:71113/71114 for 2.5 on RHEL 8/9, RHSA-2026:71177/71179) and restart the automation-controller services - a control-plane service restart, no node reboot. Treat any password-type survey answer that a JobTemplate Admin could have reached as exposed and rotate it; review who holds that delegated role in the meantime.
References
Related entries
- GlusterFS (brick, mknod): Mknod can create device nodes that point at real devices on the storage server, so a clientCVE-2018-10923 · GlusterFS (brick, mknod)High
- HashiCorp Vault: GCP secrets engine drops existing IAM Conditions when creating/updating rolesetsCVE-2023-5077 · HashiCorp VaultHigh
- NetApp ONTAP 9 role-based access control: A user holding several remote accounts with different roles performs actionsCVE-2024-21985 · NetApp ONTAP 9 role-based access controlHigh
- HashiCorp Nomad Enterprise: Jobs using the policy-override option bypass mandatory Sentinel policiesCVE-2025-3744 · HashiCorp Nomad EnterpriseHigh
- Grafana: Client path traversal + open redirectCVE-2025-4123 · GrafanaHigh
- Sidero Omni: Reader role can read the full CA secrets bundle of an imported Talos clusterCVE-2026-45726 · Sidero Omni (ImportedClusterSecrets resource access rules)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.