VYPR

Ansible Automation Platform

by Red Hat

CVEs (52)

  • CVE-2023-44487HigKEVOct 10, 2023
    risk 0.65cvss 7.5epss 1.00

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2026-84719CriSep 23, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and…

  • CVE-2026-84502CriSep 23, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a…

  • CVE-2026-84474CriSep 23, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity…

  • CVE-2026-84691HigSep 23, 2026
    risk 0.57cvss 8.7epss 0.00

    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because…

  • CVE-2026-84683HigSep 23, 2026
    risk 0.57cvss 8.7epss 0.00

    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML.…

  • CVE-2025-49521HigJun 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on…

  • CVE-2025-49520HigJun 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows an authenticated attacker to inject arguments and execute arbitrary commands on the EDA worker. In…

  • CVE-2021-4112HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.

  • CVE-2025-14025HigJan 8, 2026
    risk 0.55cvss 8.5epss 0.00

    A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g.,…

  • CVE-2026-84486HigSep 23, 2026
    risk 0.53cvss 8.2epss 0.01

    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) and are routed in production builds because…

  • CVE-2026-18141HigJul 31, 2026
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL…

  • CVE-2024-1657HigApr 25, 2024
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting…

  • CVE-2026-84499HigSep 23, 2026
    risk 0.50cvss 7.7epss 0.00

    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened…

  • CVE-2026-84706HigSep 23, 2026
    risk 0.49cvss 7.6epss 0.00

    A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables…

  • CVE-2023-50782HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

  • CVE-2023-3971HigOct 4, 2023
    risk 0.48cvss 7.3epss 0.01

    An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

  • CVE-2026-85475HigSep 23, 2026
    risk 0.47cvss 7.2epss 0.00

    A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE…

  • CVE-2023-4237HigOct 4, 2023
    risk 0.47cvss 7.3epss 0.00

    A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality,…

  • CVE-2025-9909MedFeb 27, 2026
    risk 0.44cvss 6.7epss 0.00

    A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator…

Page 1 of 3