CVE-2025-2877: Red Hat Ansible Automation Platform 2.4 For Rhel 8

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.

Affected products

  • Red Hat Red Hat Ansible Automation Platform 2.4 For Rhel 8: before 0:1.0.8-2.el8ap (fixed in 0:1.0.8-2.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.4 For Rhel 9: before 0:1.0.8-2.el9ap (fixed in 0:1.0.8-2.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:1.1.4-2.el8ap (fixed in 0:1.1.4-2.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:1.1.4-2.el9ap (fixed in 0:1.1.4-2.el9ap)

Published 2025-03-28. Last modified 2026-06-17.