CVE-2025-2877: Red Hat Ansible Automation Platform 2.4 For Rhel 8
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.
Affected products
- Red Hat Red Hat Ansible Automation Platform 2.4 For Rhel 8: before 0:1.0.8-2.el8ap (fixed in 0:1.0.8-2.el8ap)
- Red Hat Red Hat Ansible Automation Platform 2.4 For Rhel 9: before 0:1.0.8-2.el9ap (fixed in 0:1.0.8-2.el9ap)
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:1.1.4-2.el8ap (fixed in 0:1.1.4-2.el8ap)
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:1.1.4-2.el9ap (fixed in 0:1.1.4-2.el9ap)
Published 2025-03-28. Last modified 2026-06-17.