Red Hat / Ansible Automation Platform
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-44495 | Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge | HIGH | 7.7 | Jun 11, 2026 |
| CVE-2026-46625 | JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection | HIGH | 7.5 | Jun 10, 2026 |
| CVE-2026-48710 KEV | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks | MEDIUM | 6.5 | May 26, 2026 |
| CVE-2025-57847 | Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions | MEDIUM | 6.4 | Apr 8, 2026 |
| CVE-2025-9909 | Aap-gateway: improper path validation in gateway allows credential exfiltration | MEDIUM | 6.7 | Feb 27, 2026 |
| CVE-2025-9908 | Event-driven-ansible: sensitive internal headers disclosure in aap eda event streams | MEDIUM | 6.7 | Feb 27, 2026 |
| CVE-2025-9907 | Event-driven-ansible: event stream test mode exposes sensitive headers in aap eda | MEDIUM | 6.7 | Feb 27, 2026 |
| CVE-2025-53861 | Aap: sensitive cookie(s) set without security flags | LOW | 3.1 | Jul 11, 2025 |
| CVE-2025-53862 | Aap: aap-gateway: automation-hub: sensitive information disclosure | LOW | 3.5 | Jul 11, 2025 |
| CVE-2024-10033 | Aap-gateway: xss on aap-gateway | MEDIUM | 6.1 | Oct 16, 2024 |
| CVE-2024-0690 | Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration | MEDIUM | 5.5 | Feb 6, 2024 |
| CVE-2023-50782 | Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659 | HIGH | 8.7 | Feb 5, 2024 |
| CVE-2023-5115 | Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files | MEDIUM | 6.3 | Dec 18, 2023 |
| CVE-2023-5764 | Ansible: template injection | HIGH | 7.8 | Dec 12, 2023 |
| CVE-2023-5189 | Hub: insecure galaxy-importer tarfile extraction | MEDIUM | 6.5 | Nov 14, 2023 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2023-3971 | Controller: html injection in custom login info | HIGH | 7.3 | Oct 4, 2023 |
| CVE-2023-4380 | Platform: token exposed at importing project | MEDIUM | 6.3 | Oct 4, 2023 |
| CVE-2023-4237 | Platform: ec2_key module prints out the private key directly to the standard output | HIGH | 7.8 | Oct 4, 2023 |
| CVE-2022-3644 | Pulp: Tokens stored in plaintext | MEDIUM | 5.5 | Oct 25, 2022 |
| CVE-2022-3205 | Controller: cross site scripting in automation controller ui | MEDIUM | 6.1 | Sep 13, 2022 |
| CVE-2022-1632 | Openshift: ClusterIP Service TLS certificate not checked by route controller if re-encrypt Route destinationCACertificate field is explicitly set to default se… | MEDIUM | 6.5 | Sep 1, 2022 |
| CVE-2021-4112 | ansible-tower: Privilege escalation via job isolation escape | HIGH | 8.8 | Aug 25, 2022 |
| CVE-2022-2568 | Ansible: Logic flaw leads to privilage escalation | HIGH | 7.2 | Aug 18, 2022 |
| CVE-2021-3681 | ansible: Secrets leakage vulnerability with ansible collections and ansible galaxy | MEDIUM | 5.5 | Apr 18, 2022 |
Showing 1 to 25 of 27 CVEs