CVE-2025-7738: Python3.11-django-ansible-base: sensitive authenticator secrets returned in clear text via api in aap

Published Jul 17, 2025
·
Updated

A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.

Other sources

A sensitive information disclosure vulnerability exists in the Gateway API of Ansible Automation Platform. When fetching the configuration of certain authenticators (GitHub Enterprise or GitHub Enterprise Org), the API returns the OAuth2 client secret in clear text instead of redacting or masking it (e.g., returning $encrypted$). This flaw is present in the endpoint /api/gateway/v1/authenticators/<authenticator ID>/ and can be reproduced by administrators or auditors with access. While not directly exploitable over the network by unauthorized actors, it exposes a high-value secret that could be misused if accessed by a malicious insider or compromised privileged account.

Red Hat

Affected Software

2 affected components
Red Hat Ansible Automation Platform
pypi/python3.11-django-ansible-base

Event History

Jul 17, 2025
Data Sourced
via Red Hat·05:13 AM
DescriptionSeverityAffected Software
Jul 31, 2025
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Jul 16, 57567
Event
via FIRST·03:34 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-7738?

CVE-2025-7738 is considered a high severity vulnerability due to the exposure of sensitive client secrets.

2

What components are affected by CVE-2025-7738?

CVE-2025-7738 affects the Gateway API within the Red Hat Ansible Automation Platform.

3

How do I fix CVE-2025-7738?

To fix CVE-2025-7738, you should update your Ansible Automation Platform to the latest version where the vulnerability has been addressed.

4

Who is impacted by CVE-2025-7738?

Administrators and auditors accessing authenticator configurations in Ansible Automation Platform are primarily impacted by CVE-2025-7738.

5

What type of information is exposed in CVE-2025-7738?

CVE-2025-7738 exposes client secrets for certain GitHub Enterprise authenticators in clear text.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203