« Volver al listado

CVE-2025-57847

Estado: ModificadaMedia (6.4)—

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-57847",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-57847",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-08T15:42:54.958669Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:ansible_core:2.16::el8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.16",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789001438",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform/ee-minimal-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_core:2.16::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.16",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789023765",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform/ee-minimal-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_core:2.18::el8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.18",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789023329",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform/ee-minimal-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_core:2.18::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.18",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789001715",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform/ee-minimal-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.5::el8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.5",
          "versions": [
            {
              "status": "unaffected",
              "version": "1784035663",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform-25/ee-minimal-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.5::el8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.5",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789634812",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform-25/de-minimal-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.5::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.5",
          "versions": [
            {
              "status": "unaffected",
              "version": "1784051694",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform-25/ee-minimal-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.5::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.5",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789654540",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform-25/de-minimal-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.6::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.6",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789658734",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform-26/de-minimal-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.6::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.6",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789661423",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform-26/de-supported-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.6::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.6",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789654312",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform-26/ee-minimal-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.7::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.7",
          "versions": [
            {
              "status": "unaffected",
              "version": "1788901236",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform-27/ee-minimal-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.7::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.7",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789582543",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform-27/de-minimal-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2.7::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2.7",
          "versions": [
            {
              "status": "unaffected",
              "version": "1789584820",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ansible-automation-platform-27/de-supported-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2",
          "packageName": "ansible-automation-platform-24/controller-rhel8",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2",
          "packageName": "ansible-automation-platform-24/ee-29-rhel8",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2",
          "packageName": "ansible-automation-platform-25/ansible-dev-tools-rhel8",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2",
          "packageName": "ansible-automation-platform-25/controller-rhel8-operator",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2",
          "packageName": "ansible-automation-platform-26/ee-supported-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2",
          "packageName": "ansible-automation-platform/ee-29-rhel8",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ansible_automation_platform:2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Ansible Automation Platform 2",
          "packageName": "ansible-automation-platform-tech-preview/ansible-devspaces-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-04-08T14:16:25.577",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:42141",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:42144",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:66482",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:66485",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:66486",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:66487",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:67279",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:71177",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:71179",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:71192",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:71210",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2025-57847",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2391092",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container."
    },
    {
      "lang": "es",
      "value": "Una falla de escalada de privilegios en un contenedor fue encontrada en ciertas imágenes de Ansible Automation Platform. Este problema surge porque el archivo /etc/p4ssd se crea con permisos de escritura para el grupo durante el proceso de construcción. En ciertas condiciones, un atacante que puede ejecutar comandos dentro de un contenedor afectado, incluso como un usuario no-root, puede aprovechar su pertenencia al grupo root para modificar el archivo /etc/p4ssd. Esta vulnerabilidad permite a un atacante añadir un nuevo usuario con cualquier UID arbitrario, incluyendo UID 0, obteniendo privilegios de root completos dentro del contenedor."
    }
  ],
  "lastModified": "2026-09-24T07:16:30.817",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:ansible_automation_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54CB7869-8F6E-4A79-8545-EBD5B2070F5B",
              "versionEndIncluding": "2.6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}