RHSA-2025:23069HighCVSS 8.3
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
🔗 CVE IDs covered (6)
CVE-2025-9907 · pendingCVE-2025-9908 · pendingCVE-2025-9909 · pendingCVE-2025-58754 →CVE-2025-59530 →CVE-2025-64459 →
📋 Description
CVE-2025-9907 — event-driven-ansible: Event Stream Test Mode Exposes Sensitive Headers in AAP EDA CVE-2025-9908 — event-driven-ansible: Sensitive Internal Headers Disclosure in AAP EDA Event Streams CVE-2025-9909 — aap-gateway: Improper Path Validation in Gateway Allows Credential Exfiltration CVE-2025-58754 — axios: Axios DoS via lack of data size check CVE-2025-59530 — github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame CVE-2025-64459 — django: Django SQL injection
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2025:23069
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392834
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2394735
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2403125
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2412651
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23069.json