Credential Theft Vulnerability in Red Hat Ansible Automation Platform
CVE-2025-9909

6.7MEDIUM

What is CVE-2025-9909?

A vulnerability exists in the route creation component of the Red Hat Ansible Automation Platform Gateway. This flaw allows attackers to exploit misleading routes initiated by a double-slash (//) prefix in the gateway_path. A compromised or socially engineered administrator can effectively create a honey-pot route designed to intercept and exfiltrate user credentials. This manipulation opens the door for attackers to maintain persistent access or set up a backdoor, even after original permissions have been revoked, posing a significant risk to sensitive user data and system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Red Hat Ansible Automation Platform 2.5 sha256:93b5d66f1fa8a3241d999df47c8430c13fa11b751b5fc3d4a8fd2a39d282b3fd

Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:3.1.1-1.el8ap

Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:25.12.0-1.el8ap

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Elijah DeLee (Red Hat).
.