← Back

Ansible Automation Platform

ansible_automation_platform

Vendor: Redhat • 24 CVEs

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Ansible Automation Platform
May 1, 2026
Apr 8, 2026
N/A· v4
6.4 MEDIUM· v3
N/A· v2
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certai...Show more
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container.Show less
1Redhat
3Ansible Automation Platform
Ansible DeveloperAnsible Inside
Mar 25, 2026
Feb 27, 2026
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gatew...Show more
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.Show less
1Redhat
3Ansible Automation Platform
Ansible DeveloperAnsible Inside
Mar 25, 2026
Feb 27, 2026
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as...Show more
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By exfiltrating these headers, an attacker could spoof trusted requests, escalate privileges, or perform malicious event injection.Show less
1Redhat
3Ansible Automation Platform
Ansible DeveloperAnsible Inside
Mar 26, 2026
Feb 27, 2026
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the tes...Show more
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.Show less
1Redhat
1Ansible Automation Platform
Aug 11, 2025
Jul 11, 2025
N/A· v4
3.5 LOW· v3
N/A· v2
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
1Redhat
1Ansible Automation Platform
Aug 11, 2025
Jul 11, 2025
N/A· v4
3.1 LOW· v3
N/A· v2
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.
1Redhat
3Ansible Automation Platform
Ansible DeveloperAnsible Inside
Mar 26, 2025
Oct 16, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL,...Show more
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data.Show less
2Fedoraproject
Redhat
6Ansible
Ansible Automation PlatformAnsible Developer+3 more
Nov 4, 2025
Feb 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. D...Show more
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.Show less
3Couchbase
Cryptography.ioRedhat
5Ansible Automation Platform
Couchbase ServerCryptography+2 more
Mar 24, 2026
Feb 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive...Show more
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.Show less
2Debian
Redhat
4Ansible Automation Platform
Ansible DeveloperAnsible Inside+1 more
Dec 6, 2024
Dec 18, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file...Show more
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.Show less
2Fedoraproject
Redhat
6Ansible
Ansible Automation PlatformAnsible Developer+3 more
Nov 21, 2024
Dec 12, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted...Show more
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.Show less
1Redhat
2Ansible Automation Platform
Satellite
Dec 6, 2024
Nov 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the d...Show more
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.Show less
33Akka
AmazonApache+30 more
165.net
3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 more
May 12, 2026
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
1Redhat
3Ansible Automation Platform
Ansible DeveloperAnsible Inside
Nov 21, 2024
Oct 4, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, r...Show more
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.Show less
1Redhat
2Ansible Automation Platform
Ansible Collection
Nov 21, 2024
Oct 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the l...Show more
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.Show less
1Redhat
4Ansible Automation Controller
Ansible Automation PlatformAnsible Developer+1 more
Nov 21, 2024
Oct 4, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
2Pulpproject
Redhat
4Ansible Automation Platform
Pulp AnsibleSatellite+1 more
May 7, 2025
Oct 25, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
1Redhat
1Ansible Automation Platform
Nov 21, 2024
Sep 13, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection
2Fedoraproject
Redhat
3Ansible Automation Platform
FedoraOpenshift Container Platform
Nov 21, 2024
Sep 1, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allo...Show more
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.Show less
1Redhat
4Ansible Automation Platform
Ansible Automation Platform Early AccessAnsible Automation Platform Text Only Advisories+1 more
Nov 21, 2024
Aug 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the iso...Show more
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.Show less