CVE-2025-53862: Aap: aap-gateway: automation-hub: sensitive information disclosure
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
Other sources
A flaw was found in Ansible. Three API endpoints were accessed and returned verbose, unauthenticated responses, which may contain important information for an malicious user to perform other attacks.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53862?
CVE-2025-53862 has been classified with a high severity due to the potential unauthorized access to sensitive data.
How do I fix CVE-2025-53862?
To fix CVE-2025-53862, update Red Hat Ansible to the latest patched version provided by Red Hat.
What are the implications of CVE-2025-53862 on my Ansible deployment?
The implications of CVE-2025-53862 include the risk of data exposure from three vulnerable API endpoints.
Who is affected by CVE-2025-53862?
CVE-2025-53862 affects users of Red Hat Ansible due to undisclosed API vulnerabilities.
Is authentication required for accessing the endpoints affected by CVE-2025-53862?
No, authentication is not required to access the vulnerable endpoints in CVE-2025-53862, posing a significant risk.