CVE-2025-9909
- EPSS 0.01%
- Veröffentlicht 27.02.2026 07:30:00
- Zuletzt bearbeitet 25.03.2026 20:18:06
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or social...
CVE-2025-9908
- EPSS 0%
- Veröffentlicht 27.02.2026 07:29:32
- Zuletzt bearbeitet 25.03.2026 20:19:13
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*)...
CVE-2025-9907
- EPSS 0.01%
- Veröffentlicht 27.02.2026 07:29:06
- Zuletzt bearbeitet 26.03.2026 16:56:31
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event ...
CVE-2024-10033
- EPSS 1.1%
- Veröffentlicht 16.10.2024 17:15:13
- Zuletzt bearbeitet 26.03.2025 05:15:39
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting...
CVE-2024-0690
- EPSS 0.06%
- Veröffentlicht 06.02.2024 12:15:55
- Zuletzt bearbeitet 04.11.2025 19:16:27
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this iss...
CVE-2023-5115
- EPSS 0.66%
- Veröffentlicht 18.12.2023 14:15:10
- Zuletzt bearbeitet 06.12.2024 11:15:07
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path...
CVE-2023-5764
- EPSS 0.07%
- Veröffentlicht 12.12.2023 22:15:22
- Zuletzt bearbeitet 21.11.2024 08:42:26
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating i...
CVE-2023-3971
- EPSS 0.4%
- Veröffentlicht 04.10.2023 15:15:12
- Zuletzt bearbeitet 21.11.2024 08:18:25
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
CVE-2023-4380
- EPSS 0.07%
- Veröffentlicht 04.10.2023 15:15:12
- Zuletzt bearbeitet 21.11.2024 08:34:58
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confid...