Skip to main content
EPSS 0.6%top 56%

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update

0
High
Published: 10/22/2025 (10/22/2025, 13:21:59 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * python3.11-django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682) * automation-gateway: tar-fs symlink validation bypass (CVE-2025-59343) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Automation Platform * Azure AD authentication now searches more fields to find the username override field specified. If not found it will log a warning message indicating which fields are valid (AAP-53789) * Support TLSv1.3 on server-to-server requests, where previously services which only supported TLSv1.3 would not work (AAP-49456) * Added a step in the subscription wizard that allows the user to configure automation analytics (AAP-55094) * Subscription credentials can no longer be viewed/edited from the system settings page (AAP-55014) * Fixed an issue where the settings displayed "Red Hat" inconsistently in the API and UI (AAP-54277) * Fixed a bug where platform auditors were not able to see Automation Execution and Platform level settings (AAP-53975) * Fixed an issue where some fields were missing the autocomplete = new-password setting (AAP-53934) * Fixed an issue where AAP could not set/create a playbook when using branch override (AAP-52566) * Empty strings are no longer displayed in the extra variables field on the Jobs > Details page (AAP-49448) * Added two new toggle options on the subscription wizard to allow for fetching subscriptions using basic authentication (AAP-47865) * Fixed validation of prompt-on-launch credentials in a workflow job template (AAP-40540) * Fixed an issue for comments in extra vars sections, all comments in YAML are now persisted on create and edit operations for a resource (AAP-37071) * Updated error handling in the Authenticator form to match other forms in the Platform UI (AAP-22928) * automation-gateway has been updated to 2.5.20251022 * automation-gateway-proxy has been updated to 2.5.10-3 for RHEL8 * automation-gateway-proxy has been updated to 2.6.6-4 for RHEL9 * python3.11-django-ansible-base has been updated to 2.5.20251022 Automation controller * Fixed an issue where the ansible.platform collection did not work with the default Red Hat Ansible Automation Platform credential type (AAP-55685) * Fixed an issue in callback receiver and dispatcher crash loop state caused by re-running the installer with modified inventory hostname (AAP-55638) * Added support for Red Hat username and password for the subscription management API (AAP-54976) * Fixes system_administrator role creation race condition which most commonly happened on new openshift deployments resulting in the default instance group not being created (AAP-54964) * Fixed an issue where Grafana notifications couldn't have an empty dashboard ID or panel ID (AAP-54654) * Improved stability on long-running jobs, clusters under heavy load and network flakiness in receptor (AAP-53742) * Fixed Platform Auditor to view controller settings (AAP-53345) * Added missing instruction to set an environment variable in the CLI in order to achieve compatibility with the current release (AAP-37812) * Fixed Platform Auditor to view Metrics API endpoint (AAP-36492) * automation-controller has been updated to 4.6.21 * receptor has been updated to 1.6.0 Automation hub * Fixed an issue where _ui/v2/ user detail displayed the data correctly (AAP-55957) * automation-hub has been updated to 4.10.9 * python3.11-galaxy-ng has been updated to 4.10.9 * python3.11-galaxy-importer has been updated to 0.4.34 Container-based Ansible Automation Platform * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55181) * Implemented preflight ansible-core version validation (AAP-54931) * Fixed a bug where Ansible would fail to gather the system's UUID for Linux on Power (AAP-54540) * containerized installer setup has been updated to 2.5-20 RPM-based Ansible Automation Platform * Fixed an issue where setting automationgateway_disable_https=false resulted in install failure (AAP-55475) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55184) * Fixed issue where RESOURCE_KEY SECRET_KEY was not updated when restoring from a different environment (AAP-54944) * Fixed issue where EDA DE credentials fa

Affected software

Affected versions
>=2.5.0 <2.6.0Red HatRed Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.5 for RHEL 9

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 16:48:34 UTC

Technical Analysis

This advisory covers two security fixes in Red Hat Ansible Automation Platform 2.5: CVE-2025-59343 is a symlink validation bypass vulnerability in the automation-gateway's tar-fs handling, which could allow an attacker to bypass security checks on symbolic links during archive extraction. CVE-2025-59682 is a potential partial directory-traversal vulnerability in python3.11-django's archive.extract() function, which could allow unauthorized access to filesystem paths. The advisory includes updates to automation-gateway, python3.11-django-ansible-base, and other components to remediate these issues. Additional bug fixes and feature improvements are also included in this release.

Potential Impact

Successful exploitation of these vulnerabilities could allow an attacker to bypass security restrictions related to file extraction and symbolic link validation, potentially leading to unauthorized file access or modification within the Ansible Automation Platform environment. This could compromise the integrity of automation tasks or expose sensitive data. The vulnerabilities are rated with high severity by Red Hat Product Security.

Mitigation Recommendations

Red Hat has released updated packages for Ansible Automation Platform 2.5 that address these vulnerabilities. Users should apply the official security update RHSA-2025:18979 promptly to remediate these issues. The advisory includes updated versions of automation-gateway (2.5.20251022), automation-gateway-proxy, python3.11-django-ansible-base, and other components. No additional mitigation steps are indicated beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:18979
Cve Count
2
Additional Cves
["CVE-2025-59682"]

Threat ID: 6a1f4e87e29bf47b50080e7d

Added to database: 06/02/2026, 21:43:35 UTC

Last enriched: 08/16/2026, 16:48:34 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 154

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses