{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-2877","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"PUBLISHED","assignerShortName":"redhat","dateReserved":"2025-03-27T17:06:26.480Z","datePublished":"2025-03-28T14:05:18.308Z","dateUpdated":"2026-03-20T17:57:38.922Z"},"containers":{"cna":{"title":"Event-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activation with verbosity set to debug in eda","metrics":[{"other":{"content":{"value":"Important","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to \"debug\", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any \"debug\" action in a rulebook and also affects Event Streams."}],"affected":[{"versions":[{"status":"affected","version":"0","lessThan":"1.1.6","versionType":"semver"}],"packageName":"ansible-rulebook","collectionURL":"https://github.com/ansible/ansible-rulebook","defaultStatus":"unaffected"},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.4 for RHEL 8","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-rulebook","defaultStatus":"affected","versions":[{"version":"0:1.0.8-2.el8ap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:ansible_automation_platform_developer:2.4::el9","cpe:/a:redhat:ansible_automation_platform:2.4::el8","cpe:/a:redhat:ansible_automation_platform:2.4::el9","cpe:/a:redhat:ansible_automation_platform_developer:2.4::el8"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.4 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-rulebook","defaultStatus":"affected","versions":[{"version":"0:1.0.8-2.el9ap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:ansible_automation_platform_developer:2.4::el9","cpe:/a:redhat:ansible_automation_platform:2.4::el8","cpe:/a:redhat:ansible_automation_platform:2.4::el9","cpe:/a:redhat:ansible_automation_platform_developer:2.4::el8"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 8","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-rulebook","defaultStatus":"affected","versions":[{"version":"0:1.1.4-2.el8ap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8","cpe:/a:redhat:ansible_automation_platform:2.5::el8","cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9","cpe:/a:redhat:ansible_automation_platform:2.5::el9"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 9","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-rulebook","defaultStatus":"affected","versions":[{"version":"0:1.1.4-2.el9ap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8","cpe:/a:redhat:ansible_automation_platform:2.5::el8","cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9","cpe:/a:redhat:ansible_automation_platform:2.5::el9"]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2025:3636","name":"RHSA-2025:3636","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/errata/RHSA-2025:3637","name":"RHSA-2025:3637","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/security/cve/CVE-2025-2877","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2355540","name":"RHBZ#2355540","tags":["issue-tracking","x_refsource_REDHAT"]},{"url":"https://github.com/ansible/ansible-rulebook/pull/767"}],"datePublic":"2025-03-25T00:00:00.000Z","problemTypes":[{"descriptions":[{"cweId":"CWE-1295","description":"Debug Messages Revealing Unnecessary Information","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-1295: Debug Messages Revealing Unnecessary Information","workarounds":[{"lang":"en","value":"Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability."}],"timeline":[{"lang":"en","time":"2025-03-27T16:59:44.171Z","value":"Reported to Red Hat."},{"lang":"en","time":"2025-03-25T00:00:00.000Z","value":"Made public."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-03-20T17:57:38.922Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-03-28T14:31:03.979042Z","id":"CVE-2025-2877","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-03-28T14:31:12.023Z"}}]}}