VendorsRed Hatansible_automation_platform2.0
Vulnerabilities

Red Hat Ansible Automation Platform 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2021-4112
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
Published 2022-08-25 · Modified
8.8EPSS 0.002
CVE-2024-7143
Pulpcore: rbac permissions incorrectly assigned in tasks that create objects
Published 2024-08-07 · Modified
8.3EPSS 0.006
CVE-2023-4237
Platform: ec2_key module prints out the private key directly to the standard output
Published 2023-10-04 · Modified
7.8EPSS 0.003
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2023-50782
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
Published 2024-02-05 · Modified
7.5EPSS 0.011
CVE-2026-46625
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
Published 2026-06-10 · Modified
7.5EPSS 0.010
CVE-2022-2568
A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.
Published 2022-08-18 · Modified
6.5EPSS 0.009
CVE-2023-5189
Hub: insecure galaxy-importer tarfile extraction
Published 2023-11-14 · Modified
6.5EPSS 0.008
CVE-2022-1632
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
Published 2022-09-01 · Modified
6.5EPSS 0.004
CVE-2022-3205
Controller: cross site scripting in automation controller ui
Published 2022-09-13 · Modified
6.1EPSS 0.005
CVE-2022-3644
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
Published 2022-10-25 · Modified
5.5EPSS 0.003
CVE-2025-53862
Aap: aap-gateway: automation-hub: sensitive information disclosure
Published 2025-07-11 · Analyzed
3.5EPSS 0.002
CVE-2025-53861
Aap: sensitive cookie(s) set without security flags
Published 2025-07-11 · Analyzed
3.1EPSS 0.001