CVE-2024-11483

Source
https://cve.org/CVERecord?id=CVE-2024-11483
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11483.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-11483
Downstream
Published
2024-11-25T03:54:34Z
Modified
2026-08-12T03:51:46Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N CVSS Calculator
Summary
Automation-gateway: aap-gateway: improper scope handling in oauth2 tokens for aap 2.5
Details

A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on ansible_base.oauth2_provider for OAuth2 authentication. While the impact is limited to actions within the user’s assigned permissions, it undermines scoped access controls, potentially allowing unintended modifications in the application and consuming services.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11483.json"
}
References

Affected packages

Git / github.com/ansible/django-ansible-base

Affected ranges

Type
GIT
Repo
https://github.com/ansible/django-ansible-base
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "v2024.10.17"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2024.*
2024.1.31
2024.10.17
2024.2.12
2024.4.12
2024.4.15
2024.4.18
2024.4.23
2024.4.25
2024.5.1
2024.5.16
2024.5.17
2024.5.18
2024.5.23
2024.5.31
2024.5.6
2024.6.11
2024.6.26
2024.6.6
2024.6.8
2024.7.1
2024.7.17
2024.8.1
2024.8.19
2024.8.22
2024.8.26
2024.8.28
2024.8.8
2024.8.9
2024.9.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11483.json"