Event-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activation with verbosity set to debug in eda
Published Mar 28, 2025
6.5
MEDIUMCVSS 3.1
EPSS 0.41%
Description
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.
Affected products
No data.
No data.
No data.
Red Hat Ansible Automation Platform 2.4 for RHEL 8
ansible-rulebook-0:1.0.8-2.el8ap
Fixed · RHSA-2025:3636
Red Hat Ansible Automation Platform 2.4 for RHEL 9
ansible-rulebook-0:1.0.8-2.el9ap
Fixed · RHSA-2025:3636
Red Hat Ansible Automation Platform 2.5 for RHEL 8
ansible-rulebook-0:1.1.4-2.el8ap
Fixed · RHSA-2025:3637
Red Hat Ansible Automation Platform 2.5 for RHEL 9
ansible-rulebook-0:1.1.4-2.el9ap
Fixed · RHSA-2025:3637
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2.4 for RHEL 8 | ansible-rulebook-0:1.0.8-2.el8ap | Fixed | RHSA-2025:3636 |
| Red Hat Ansible Automation Platform 2.4 for RHEL 9 | ansible-rulebook-0:1.0.8-2.el9ap | Fixed | RHSA-2025:3636 |
| Red Hat Ansible Automation Platform 2.5 for RHEL 8 | ansible-rulebook-0:1.1.4-2.el8ap | Fixed | RHSA-2025:3637 |
| Red Hat Ansible Automation Platform 2.5 for RHEL 9 | ansible-rulebook-0:1.1.4-2.el9ap | Fixed | RHSA-2025:3637 |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
This flaw is rated as Important since it may potentially expose cleartext passwords to the user who started the Activation and to any user who has been granted privileges to observe the Activation.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/errata/RHSA-2025:3636 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:3637 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-2877 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2355540 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-8615 Advisory
- https://github.com/ansible/ansible-rulebook/pull/767
- https://nvd.nist.gov/vuln/detail/CVE-2025-2877
- https://www.cve.org/CVERecord?id=CVE-2025-2877
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:3636 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2025:3637 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2025-2877 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2355540 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-8615 | Advisory | |
| https://github.com/ansible/ansible-rulebook/pull/767 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2025-2877 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-2877 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data