First published: Thu Mar 27 2025(Updated: )
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ansible Automation Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2877 is classified as a moderate severity vulnerability due to the exposure of sensitive information.
To mitigate CVE-2025-2877, disable debug verbosity in Ansible Automation Platform configurations.
CVE-2025-2877 affects all versions of the Ansible Automation Platform that allow debug-level logging.
CVE-2025-2877 exposes inventory passwords in plain text when debug verbosity is enabled.
As a workaround for CVE-2025-2877, users should avoid using debug verbosity in their rulebook activations.