A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.
Workaround:
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2025:12772 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2025-5988 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2371644 | issue tracking |