CVE-2025-2877: Event-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activation with verbosity set to debug in eda
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.
Other sources
Inventory passwords are exposed in plain text when starting a rulebook activation with verbosity set to debug. This issue is reproducible for any "debug" action in a rulebook and also affects Event Streams, exposing postgres passwords.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2877?
CVE-2025-2877 is classified as a moderate severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2025-2877?
To mitigate CVE-2025-2877, disable debug verbosity in Ansible Automation Platform configurations.
Which versions of Ansible Automation Platform are affected by CVE-2025-2877?
CVE-2025-2877 affects all versions of the Ansible Automation Platform that allow debug-level logging.
What type of data is exposed in CVE-2025-2877?
CVE-2025-2877 exposes inventory passwords in plain text when debug verbosity is enabled.
Is there a workaround for CVE-2025-2877?
As a workaround for CVE-2025-2877, users should avoid using debug verbosity in their rulebook activations.