CVE-2025-2877
Estado: AplazadaMedia (6.5)—
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.41%
- Percentil entre todas las CVEs puntuadas: 33
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-1295
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-2877",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-2877",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-03-28T14:31:03.979042Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.1.6",
"versionType": "semver"
}
],
"packageName": "ansible-rulebook",
"collectionURL": "https://github.com/ansible/ansible-rulebook",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:ansible_automation_platform_developer:2.4::el9",
"cpe:/a:redhat:ansible_automation_platform:2.4::el8",
"cpe:/a:redhat:ansible_automation_platform:2.4::el9",
"cpe:/a:redhat:ansible_automation_platform_developer:2.4::el8"
],
"vendor": "Red Hat",
"product": "Red Hat Ansible Automation Platform 2.4 for RHEL 8",
"versions": [
{
"status": "unaffected",
"version": "0:1.0.8-2.el8ap",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "ansible-rulebook",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:ansible_automation_platform_developer:2.4::el9",
"cpe:/a:redhat:ansible_automation_platform:2.4::el8",
"cpe:/a:redhat:ansible_automation_platform:2.4::el9",
"cpe:/a:redhat:ansible_automation_platform_developer:2.4::el8"
],
"vendor": "Red Hat",
"product": "Red Hat Ansible Automation Platform 2.4 for RHEL 9",
"versions": [
{
"status": "unaffected",
"version": "0:1.0.8-2.el9ap",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "ansible-rulebook",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8",
"cpe:/a:redhat:ansible_automation_platform:2.5::el8",
"cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9",
"cpe:/a:redhat:ansible_automation_platform:2.5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
"versions": [
{
"status": "unaffected",
"version": "0:1.1.4-2.el8ap",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "ansible-rulebook",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8",
"cpe:/a:redhat:ansible_automation_platform:2.5::el8",
"cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9",
"cpe:/a:redhat:ansible_automation_platform:2.5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
"versions": [
{
"status": "unaffected",
"version": "0:1.1.4-2.el9ap",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "ansible-rulebook",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2025-03-28T14:15:21.877",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2025:3636",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:3637",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2025-2877",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2355540",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/ansible/ansible-rulebook/pull/767",
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-1295"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to \"debug\", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any \"debug\" action in a rulebook and also affects Event Streams."
},
{
"lang": "es",
"value": "Se detectó una falla en Ansible Automation Platform's Event-Driven Ansible. En configuraciones donde el nivel de detalle está configurado como \"depuración\", las contraseñas de inventario se exponen en texto plano al iniciar la activación de un libro de reglas. Este problema existe para cualquier acción de \"depuración\" en un libro de reglas y también afecta a los flujos de eventos."
}
],
"lastModified": "2026-06-17T09:07:46.773",
"sourceIdentifier": "secalert@redhat.com"
}