Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in the AWX websocket event consumer. The consumer_access() function in awx/main/access.py maps RBAC access classes for only three event groups (job_events, workflow_events, ad_hoc_command_events). When EventConsumer.receive_json() in awx/main/consumers.py processes a subscription request for the three unmapped groups (inventory_update_events, project_update_events, system_job_events), consumer_access() returns None, causing the RBAC authorization check to be skipped entirely. The user is unconditionally subscribed to the channel. As a result, any authenticated user - regardless of role or organization membership - can subscribe to these websocket groups for any object ID and receive real-time stdout output and event_data from inventory syncs, project updates, and system jobs belonging to other organizations. This is an incomplete remediation of CVE-2020-10698, which established the RBAC mechanism but only mapped three of the six subscribable event groups. Object IDs are globally sequential UnifiedJob IDs and are trivially enumerable. Stdout data on the websocket path is not redacted (redaction exists only in REST serializers), and project update stdout may contain SCM basic-auth credentials. Verified on AWX 24.6.1; same code path confirmed on devel branch.