A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
Workaround:
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2025-53862 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2379359 | issue tracking |