CVE-2025-1801: Red Hat Ansible Automation Platform 2.5 For Rhel 8

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged user, enabling the server to be jeopardized. A user session or confidential data might be vulnerable.

Affected products

  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:2.5.20250305-1.el8ap (fixed in 0:2.5.20250305-1.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:2.5.20250305-1.el9ap (fixed in 0:2.5.20250305-1.el9ap)

Published 2025-03-03. Last modified 2026-06-17.