Redhat Ansible Automation Platform vulnerabilities

23 known vulnerabilities affecting redhat/ansible_automation_platform.

Total CVEs
23
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH7MEDIUM14LOW2

Vulnerabilities

Page 1 of 2
CVE-2025-9909MEDIUMCVSS 6.7fixed in 2.62026-02-27
CVE-2025-9909 [MEDIUM] CWE-647 CVE-2025-9909: A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This v A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credential
nvd
CVE-2025-9907MEDIUMCVSS 6.7fixed in 2.62026-02-27
CVE-2025-9907 [MEDIUM] CWE-200 CVE-2025-9907: A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accid
nvd
CVE-2025-9908MEDIUMCVSS 6.7fixed in 2.62026-02-27
CVE-2025-9908 [MEDIUM] CWE-200 CVE-2025-9908: A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By exfiltrating these headers, an attack
nvd
CVE-2025-53861LOWCVSS 3.1v2.02025-07-11
CVE-2025-53861 [LOW] CWE-319 CVE-2025-53861: A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels ca A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.
nvd
CVE-2025-53862LOWCVSS 3.5v2.02025-07-11
CVE-2025-53862 [LOW] CWE-497 CVE-2025-53862: A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
nvd
CVE-2024-10033MEDIUMCVSS 6.1v2.52024-10-16
CVE-2024-10033 [MEDIUM] CWE-79 CVE-2024-10033: A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the g A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data.
nvd
CVE-2024-0690MEDIUMCVSS 5.5v2.42024-02-06
CVE-2024-0690 [MEDIUM] CWE-117 CVE-2024-0690: An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_ An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
nvd
CVE-2023-50782HIGHCVSS 7.5v2.02024-02-05
CVE-2023-50782 [HIGH] CWE-203 CVE-2023-50782: A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decry A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
nvd
CVE-2023-5115MEDIUMCVSS 6.3v1.2v2.3+1 more2023-12-18
CVE-2023-5115 [MEDIUM] CWE-36 CVE-2023-5115: An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an att An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
nvd
CVE-2023-5764HIGHCVSS 7.8v2.42023-12-12
CVE-2023-5764 [HIGH] CWE-1336 CVE-2023-5764: A template injection flaw was found in Ansible where a user's controller internal templating operati A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
nvd
CVE-2023-5189MEDIUMCVSS 6.5v2.02023-11-14
CVE-2023-5189 [MEDIUM] CWE-23 CVE-2023-5189: A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.
nvd
CVE-2023-44487HIGHCVSS 7.5KEVPoCv2.02023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2023-4237HIGHCVSS 7.8v2.02023-10-04
CVE-2023-4237 [HIGH] CWE-497 CVE-2023-4237: A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
nvd
CVE-2023-3971MEDIUMCVSS 5.4v2.3v2.42023-10-04
CVE-2023-3971 [HIGH] CWE-80 CVE-2023-3971: An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an a An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
nvd
CVE-2023-4380MEDIUMCVSS 6.3v2.42023-10-04
CVE-2023-4380 [MEDIUM] CWE-532 CVE-2023-4380: A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incor A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
nvd
CVE-2022-3644MEDIUMCVSS 5.5v2.02022-10-25
CVE-2022-3644 [MEDIUM] CWE-256 CVE-2022-3644: The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
nvd
CVE-2022-3205MEDIUMCVSS 6.1v1.2v2.02022-09-13
CVE-2022-3205 [MEDIUM] CWE-79 CVE-2022-3205: Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection
nvd
CVE-2022-1632MEDIUMCVSS 6.5v2.02022-09-01
CVE-2022-1632 [MEDIUM] CWE-295 CVE-2022-1632: An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinatio An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
nvd
CVE-2021-4112HIGHCVSS 8.8v2.0v2.12022-08-25
CVE-2021-4112 [HIGH] CWE-552 CVE-2021-4112: A flaw was found in ansible-tower where the default installation is vulnerable to job isolation esca A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
nvd
CVE-2022-2568MEDIUMCVSS 6.5v2.1v2.2+1 more2022-08-18
CVE-2022-2568 [MEDIUM] CWE-269 CVE-2022-2568: A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.
nvd