CVE-2025-7738
Estado: AplazadaMedia (4.4)—
A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 4.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-312
Referencias
- https://access.redhat.com/errata/RHSA-2025:12772
- https://access.redhat.com/security/cve/CVE-2025-7738
- https://bugzilla.redhat.com/show_bug.cgi?id=2381589
- https://github.com/ansible/django-ansible-base/commit/e241ea4dce8df577eda15301e0a8e61be647b27b
- https://github.com/ansible/django-ansible-base/pull/773
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-7738",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7738",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-07-31T14:21:19.984926Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.7
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "Ansible",
"product": "django-ansible-base",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2025.7.22",
"versionType": "custom"
}
],
"packageName": "django-ansible-base",
"collectionURL": "https://github.com/ansible/django-ansible-base",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9",
"cpe:/a:redhat:ansible_automation_platform:2.5::el9",
"cpe:/a:redhat:ansible_automation_platform:2.5::el8",
"cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8"
],
"vendor": "Red Hat",
"product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
"versions": [
{
"status": "unaffected",
"version": "0:2.5.20250730-1.el8ap",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "python3.11-django-ansible-base",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9",
"cpe:/a:redhat:ansible_automation_platform:2.5::el9",
"cpe:/a:redhat:ansible_automation_platform:2.5::el8",
"cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8"
],
"vendor": "Red Hat",
"product": "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
"versions": [
{
"status": "unaffected",
"version": "0:2.5.20250730-1.el9ap",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "python3.11-django-ansible-base",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2025-07-31T14:15:35.177",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2025:12772",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2025-7738",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2381589",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/ansible/django-ansible-base/commit/e241ea4dce8df577eda15301e0a8e61be647b27b",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/ansible/django-ansible-base/pull/773",
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-312"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse."
},
{
"lang": "es",
"value": "Se detectó una falla en Ansible Automation Platform (AAP) donde la API Gateway devuelve el secreto del cliente para ciertos autenticadores de GitHub Enterprise en texto sin cifrar. Esta vulnerabilidad afecta a administradores o auditores que acceden a las configuraciones del autenticador. Si bien el acceso está limitado a usuarios con privilegios, la exposición en texto sin cifrar de credenciales confidenciales aumenta el riesgo de filtraciones accidentales o uso indebido."
}
],
"lastModified": "2026-06-17T10:05:33.560",
"sourceIdentifier": "secalert@redhat.com"
}