Where
-Infinity
0
Severity
9

Red Hat Ansible Automation Platform 2.6 Container Release Update

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.

1 / 2
Source: MITRE
First published (updated )
Severity
7.5
OS Command Injection, Command Injection, SSRF
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

A command injection vulnerability was found in galaxyng. The dogitcheckout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. An authenticated user who controls a git repository can create a branch or tag with shell metacharacters in the name to achieve remote code execution on the pulp worker. The vulnerable endpoint is only reachable when GALAXYENABLELEGACYROLES is set to True, which is not the default configuration.

1 / 2
Source: MITRE
First published (updated )
Severity
7.5
Infoleak
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the nolog feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

1 / 4
First published (updated )
Severity
7.3
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

First published (updated )
Severity
7
CRLF Injection

Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7
SQL Injection

Important: Red Hat Ansible Automation Platform 2.4 Container Release Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7
SQL Injection

Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform 2.5 Container Release Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7
SQL Injection

Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform Execution Environments Container Release Update

Remedy

Red Hat Ansible Automation Platform Execution Environments
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform Execution Environments Container Release Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform Execution Environments
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform Execution Environments Container Release Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform Execution Environments
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform 2.4 Container Release Update

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform 2.5 Container Release Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform 2.5 Container Release Update

1 / 2
Source: Red Hat

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform 2.4 Container Release Update

Remedy

Red Hat Ansible Automation Platform
First published (updated )
Severity
7

AAP 2.6 introduced a user auto-link strategy that automatically links an external IDP identity to an existing AAP user account when the IDP-provided email matches a user's email. The system performs no verification that the email is actually proven to belong to the authenticating user, and the behavior is hard-coded with no admin toggle. This creates two primary exploitable attack paths: (1) a regular AAP user can pre-position their account to pre-hijack a victim's first IDP login; (2) an attacker who can set an arbitrary email on a configured IDP can link to any existing AAP account, including admin accounts.

First published (updated )
Severity
7

Red Hat Ansible Automation Platform 2.6 Container Release Update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: Red Hat Ansible Automation Platform 2.3 Product Security and Bug Fix Update

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
6.7
Infoleak
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the testheaders field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.

1 / 2
Source: MITRE
First published (updated )
Severity
6.5
EPSS
0.03%
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.

1 / 2
Source: NVD
First published (updated )
Severity
6.4
AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container.

1 / 2
Source: MITRE
First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. A malicious user could use it to perform actions to impact users by using the "?next=" in a URL and hence redirecting, injecting malicious script, stealing session and data.

1 / 2
Source: Red Hat
First published (updated )
Severity
5.5
Infoleak
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

A flaw was found in Ansible where the secret information present in asyncfiles are getting disclosed when the user changes the jobdir to a world readable directory. Any secret information in an async status file will be readable by a malicious user on that system. This flaw affects Ansible Tower 3.7 and Ansible Automation Platform 1.2.

1 / 2
First published (updated )
Severity
4.4
EPSS
0.01%
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.

1 / 2
Source: MITRE
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203