Redhat

Ansible Automation Platform

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 28.03.2025 14:15:21
  • Zuletzt bearbeitet 20.03.2026 18:16:12

A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" acti...

  • EPSS 0.1%
  • Veröffentlicht 03.03.2025 15:15:16
  • Zuletzt bearbeitet 03.03.2025 15:15:16

A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the...

  • EPSS 0.09%
  • Veröffentlicht 25.11.2024 04:15:03
  • Zuletzt bearbeitet 18.12.2024 04:15:07

A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on ansible_base....

  • EPSS 0.05%
  • Veröffentlicht 12.11.2024 00:15:15
  • Zuletzt bearbeitet 18.03.2026 02:16:18

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module ...

  • EPSS 0.03%
  • Veröffentlicht 06.11.2024 10:15:06
  • Zuletzt bearbeitet 03.11.2025 23:17:34

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against th...

  • EPSS 0.85%
  • Veröffentlicht 16.10.2024 17:15:13
  • Zuletzt bearbeitet 26.03.2025 05:15:39

A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting...

  • EPSS 0.06%
  • Veröffentlicht 08.10.2024 17:15:57
  • Zuletzt bearbeitet 10.10.2024 12:56:30

A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transmitted betwe...

  • EPSS 0.04%
  • Veröffentlicht 14.09.2024 03:15:08
  • Zuletzt bearbeitet 03.11.2025 23:17:32

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_...

  • EPSS 0.04%
  • Veröffentlicht 25.04.2024 17:15:48
  • Zuletzt bearbeitet 25.02.2026 20:17:20

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data f...

  • EPSS 0.89%
  • Veröffentlicht 21.03.2024 13:00:08
  • Zuletzt bearbeitet 13.05.2025 09:15:19

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. Th...