Redhat Ansible Automation Platform vulnerabilities
27 known vulnerabilities affecting redhat/ansible_automation_platform.
Total CVEs
27
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
HIGH9MEDIUM16LOW2
Vulnerabilities
Page 2 of 2
CVE-2022-3205P4MEDIUMCVSS 6.1v1.2v2.02022-09-13
CVE-2022-3205 [MEDIUM] CWE-79 CVE-2022-3205: Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0
Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection
nvd
CVE-2024-10033P4MEDIUMCVSS 6.1v2.52024-10-16
CVE-2024-10033 [MEDIUM] CWE-79 CVE-2024-10033: A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the g
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data.
nvd
CVE-2022-3644P4MEDIUMCVSS 5.5v2.02022-10-25
CVE-2022-3644 [MEDIUM] CWE-256 CVE-2022-3644: The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
nvd
CVE-2021-3681P4MEDIUMCVSS 5.5v1.2vansible 3.3.02022-04-18
CVE-2021-3681 [MEDIUM] CWE-522 CVE-2021-3681: A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in th
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and any secrets in ``ansible`` or ``ansi
nvd
CVE-2024-0690P4MEDIUMCVSS 5.5v2.42024-02-06
CVE-2024-0690 [MEDIUM] CWE-117 CVE-2024-0690: An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
nvd
CVE-2025-53862P4LOWCVSS 3.5v2.02025-07-11
CVE-2025-53862 [LOW] CWE-497 CVE-2025-53862: A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
nvd
CVE-2025-53861P4LOWCVSS 3.1v2.02025-07-11
CVE-2025-53861 [LOW] CWE-319 CVE-2025-53861: A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels ca
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.
nvd
← Previous2 / 2