Redhat Ansible Automation Platform vulnerabilities
24 known vulnerabilities affecting redhat/ansible_automation_platform.
Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH7MEDIUM15LOW2
Vulnerabilities
Page 2 of 2
CVE-2021-3681P4MEDIUMCVSS 5.5v1.2vansible 3.3.02022-04-18
CVE-2021-3681 [MEDIUM] CWE-522 CVE-2021-3681: A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in th
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and any secrets in ``ansible`` or ``ansi
nvd
CVE-2024-0690P4MEDIUMCVSS 5.5v2.42024-02-06
CVE-2024-0690 [MEDIUM] CWE-117 CVE-2024-0690: An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
nvd
CVE-2025-53862P4LOWCVSS 3.5v2.02025-07-11
CVE-2025-53862 [LOW] CWE-497 CVE-2025-53862: A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
nvd
CVE-2025-53861P4LOWCVSS 3.1v2.02025-07-11
CVE-2025-53861 [LOW] CWE-319 CVE-2025-53861: A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels ca
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.
nvd
← Previous2 / 2