Back

MEDIUM

Event-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activation with verbosity set to debug in eda

Published Mar 28, 2025

Description

A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat statement

This flaw is rated as Important since it may potentially expose cleartext passwords to the user who started the Activation and to any user who has been granted privileges to observe the Activation.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Mar 28, 2025
Updated Mar 20, 2026
Reserved Mar 27, 2025

CISA Vulnrichment

Updated Mar 28, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Mar 25, 2025
Bugzilla 2355540

ENISA EUVD

Assigner redhat
Published Mar 28, 2025
Updated Mar 20, 2026

GitHub

No data