CVE-2025-5988
- EPSS 0.02%
- Published 04.08.2025 15:16:43
- Last modified 05.08.2025 14:34:17
A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.
CVE-2025-7738
- EPSS 0.02%
- Published 31.07.2025 14:12:02
- Last modified 04.08.2025 22:15:28
A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurat...
CVE-2025-53861
- EPSS 0.01%
- Published 11.07.2025 12:44:17
- Last modified 11.08.2025 19:21:12
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.
CVE-2025-53862
- EPSS 0.05%
- Published 11.07.2025 12:34:24
- Last modified 11.08.2025 19:20:55
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
CVE-2025-49520
- EPSS 0.12%
- Published 30.06.2025 20:45:28
- Last modified 03.07.2025 15:14:12
A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows an authenticated attacker to inject arguments and execute arbitrary commands o...
CVE-2025-49521
- EPSS 0.12%
- Published 30.06.2025 20:45:13
- Last modified 03.07.2025 15:14:12
A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or...
CVE-2025-2877
- EPSS 0.05%
- Published 28.03.2025 14:15:21
- Last modified 07.04.2025 16:15:25
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" acti...
CVE-2025-1801
- EPSS 0.05%
- Published 03.03.2025 15:15:16
- Last modified 03.03.2025 15:15:16
A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the...
- EPSS 0.12%
- Published 25.11.2024 04:15:03
- Last modified 18.12.2024 04:15:07
A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on ansible_base....
CVE-2024-11079
- EPSS 0.39%
- Published 12.11.2024 00:15:15
- Last modified 18.12.2024 04:15:06
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module ...