Flaw in Red Hat Ansible Automation Platform Event-Driven API Exposes Sensitive Credentials
CVE-2025-9907

6.7MEDIUM

What is CVE-2025-9907?

A vulnerability within the Red Hat Ansible Automation Platform's Event-Driven Ansible (EDA) Event Stream API could allow unauthorized exposure of sensitive client credentials and internal infrastructure headers when operating in test mode. This flaw may lead to the accidental exposure of user credentials, privilege escalation risks if high-value tokens are accessed, and the potential for persistent leakage of sensitive data for any user with read access to the event stream. Organizations using these products should review their configurations and take action to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Red Hat Ansible Automation Platform 2.5 sha256:07673470fb62db8bec12ec20b2500228c0c6d5108916dd936d91e10610b783d1

Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:3.1.1-1.el8ap

Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.0-1.el8ap

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Elijah DeLee (Red Hat).
.