All 34 CVE vulnerabilities found in Red Hat Ansible Automation Platform 2.5 for RHEL 8, with AI-generated Chinese analysis, references, and POCs.
This page details security vulnerabilities affecting Red Hat Ansible Automation Platform 2.5 for RHEL 8, categorized by Common Weakness Enumeration classifications. It aggregates a comprehensive list of identified flaws, including remote code execution, privilege escalation, and information disclosure issues, covering advisories published from 2023 through the present. This collection serves as a centralized resource for administrators and security analysts to monitor the security posture of this specific enterprise automation solution. Users can track vendor security advisories to stay informed about newly disclosed risks and remediation steps. The page also allows for a deeper understanding of specific weakness classes relevant to the platform, such as improper access controls or injection flaws, providing context on how these vulnerabilities typically manifest in Ansible-based environments. Additionally, it offers a historical view of the product’s vulnerability landscape, enabling teams to analyze trends and prioritize patching efforts based on severity and exploitability. By consolidating this data, the page facilitates efficient risk management and compliance auditing for organizations relying on Red Hat Ansible Automation Platform. The information is structured to help IT professionals quickly identify affected components and evaluate the potential impact on their infrastructure without needing to navigate multiple disparate sources. This streamlined approach supports proactive security maintenance and ensures that critical updates are applied promptly to mitigate known threats within the RHEL 8 ecosystem.
Vendor: Red Hat
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-9907 | Event-driven-ansible: event stream test mode exposes sensitive headers in aap eda CWE-200 | 6.7 | Medium | 2026-02-27 |
| CVE-2025-14025 | Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions CWE-279 | 8.5 | High | 2026-01-08 |
| CVE-2025-49520 | Event-driven-ansible: authenticated argument injection in git url in eda project creation CWE-88 | 8.8 | High | 2025-06-30 |
| CVE-2025-49521 | Event-driven-ansible: template injection via git branch and refspec in eda projects CWE-94 | 8.8 | High | 2025-06-30 |
All 34 known CVE vulnerabilities affecting Red Hat Ansible Automation Platform 2.5 for RHEL 8 with full Chinese analysis, references, and POCs where available.