{
  "threat_severity" : "Important",
  "public_date" : "2025-03-25T00:00:00Z",
  "bugzilla" : {
    "description" : "event-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activation with verbosity set to debug in EDA",
    "id" : "2355540",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2355540"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-1295",
  "details" : [ "A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to \"debug\", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any \"debug\" action in a rulebook and also affects Event Streams.", "A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to \"debug\", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any \"debug\" action in a rulebook and also affects Event Streams." ],
  "statement" : "This flaw is rated as Important since it may potentially expose cleartext passwords to the user who started the Activation and to any user who has been granted privileges to observe the Activation.",
  "affected_release" : [ {
    "product_name" : "Red Hat Ansible Automation Platform 2.4 for RHEL 8",
    "release_date" : "2025-04-07T00:00:00Z",
    "advisory" : "RHSA-2025:3636",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2.4::el8",
    "package" : "ansible-rulebook-0:1.0.8-2.el8ap"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2.4 for RHEL 9",
    "release_date" : "2025-04-07T00:00:00Z",
    "advisory" : "RHSA-2025:3636",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2.4::el9",
    "package" : "ansible-rulebook-0:1.0.8-2.el9ap"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
    "release_date" : "2025-04-07T00:00:00Z",
    "advisory" : "RHSA-2025:3637",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2.5::el8",
    "package" : "ansible-rulebook-0:1.1.4-2.el8ap"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2.5 for RHEL 9",
    "release_date" : "2025-04-07T00:00:00Z",
    "advisory" : "RHSA-2025:3637",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2.5::el9",
    "package" : "ansible-rulebook-0:1.1.4-2.el9ap"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-2877\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-2877\nhttps://github.com/ansible/ansible-rulebook/pull/767" ],
  "name" : "CVE-2025-2877",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}