CVE Details
Basic Information
| Title | Python3.11-django-ansible-base: sensitive authenticator secrets returned in clear text via api in aap |
|---|---|
| Type | cve |
| Published | 2025-07-31T14:12:02.648Z |
| Modified | 2025-07-31T14:21:26.556Z |
Product Information
| Vendor | Red Hat |
|---|---|
| Product | Red Hat Ansible Automation Platform 2 |
CVSS Information
| Base Score | 4.4 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N |
AI Analysis
| AI Description | A vulnerability in Ansible Automation Platform exposes client secrets for GitHub Enterprise authenticators via the Gateway API in clear text, risking accidental leaks or misuse among privileged users. |
|---|---|
| AI Severity | Medium |
| AI Vendor | Red Hat |
| AI Product | Ansible Automation Platform |
Additional Information
| CWE List | CWE-312 |
|---|---|
| Source | redhat |
Description
A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.