PT-2026-1730 · Red Hat · Ansible Automation Platform
CVE-2025-14025
·
Publicado
2026-01-08
·
Atualizado
2026-01-08
CVSS v3.1
8.5
Alta
| Vetor | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ansible Automation Platform (AAP) (affected versions not specified)
Description
A flaw exists in Ansible Automation Platform (AAP) where read-only scoped OAuth2 API Tokens, enforced at the Gateway level for Gateway-specific operations, can be used to perform write operations on backend services such as the Controller, Hub, and EDA. Exploitation of this issue could allow an attacker’s capabilities to be limited only by role based access controls (RBAC).
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ansible Automation Platform