Threats Tagged 'cve-2025-59682'
View all threats tagged with 'cve-2025-59682'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-59682'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 01/08/2026, 22:34:17 UTC Added: 05/26/2026, 20:58:24 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Update(s) and Fix(es): * Update ansible dev-tools to AAP 2.6 * Add ARM, ppc and s390x architectures Join the discussion | GCVE Database | 12/15/2025, 13:06:31 UTC Added: 06/27/2026, 22:08:17 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Update(s) and Fix(es): * Fixes issue that prevents SAML and AzureAD authentication when local user accounts share the same email address (AAP-56518) * Updated error handling in the Authenticator form to match other forms in the Platform UI. API errors for specific fields are correctly mapped to the form fields in the UI (AAP-56356) * Fixed issue with the lightspeed containers configuration when running installation for the second time over the existing AAP (AAP-56263) * Changes in the deployment and nginx configuration now allow for gunicorn and daphne to bind to :: as well, essentially allowing for seamlessly binding to IPv4 and IPv6 (dual-stack) addresses, while also enabling the operator to run in single-stack IPv6 or IPv4 scenarios (AAP-56192) * Update autocomplete settings (AAP-55783) * Fix an issue when restoring an upgraded AAP environment from 2.4 (AAP-55648) * Fixed a bug where the user could set an image without the respective version, causing the installation to enter an error loop (AAP-55642) * Fixed a bug that caused a failure to gather the job data from the controller API (AAP-55632) * Address the duplication issue by adding labels (AAP-55621) * Fixed Platform Auditor to view controller settings (AAP-55607) * Fixed an issue where setting automationgateway_disable_https=false resulted in install failure (AAP-55466) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55183) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55180) * Added a step in the subscription wizard that allows the user to configure automation analytics (AAP-55094) * Added postgres_extra_settings to AAP operators to apply postgresql configuration file level changes to managed postgres (AAP-55053) * Subscription credentials can no longer be viewed/edited from the system settings page (AAP-55014) * Add support for Red Hat username and password for the subscription management API (AAP-54975) * Fixes system_administrator role creation race condition which most commonly happened on new openshift deployments resulting in the default instance group not being created (AAP-54963) * Fixed issue where RESOURCE_KEY SECRET_KEY was not updated when restoring from a different environment (AAP-54942) * Updated ansible-builder and ansible-navigator to use EE images from ansible-automation-platform-26 namespace by default (AAP-54934) * Fix the permission list when creating a custom role and selecting the Automation Decisions project or credential types (AAP-54756) * Settings display "Red Hat" consistently in the API and UI (AAP-54276) * Fix _ui/v2/ user detail displays data correctly (AAP-54260) * Fix Ansible Lightspeed API version during AAP idle (AAP-54174) * Fix error in lightspeed service when upgrading from AAP 2.5 to AAP 2.6 (AAP-54064) * Fix "Load More" in Authentication Mapping Role dropdown doesn't work (AAP-54049) * Replaced dropdown type for decision environments on the rulebook activation form so that when there are no decision environments available, dropdown displays "No results found" instead of an empty dropdown (AAP-53844) * This version of receptor addresses improves stability on long-running jobs, clusters under heavy load and network flakiness (AAP-53742) * Axios package version was updated (AAP-53718) * Component label for Platform Auditor role was fixed to display all components (AAP-53551) * Fixed an issue where automation gateway's envoy.log did not receive logs after it was rotated (AAP-51779) * Topology layout and full screen mode were fixed (AAP-51106) * Empty strings are no longer displayed in the extra variables field on the Jobs > Details page (AAP-49448) * Added two new toggle options on the subscription wizard to allow for fetching subscriptions using basic authentication (AAP-47865) * Controller Red Hat Ansible Automation Platform now works with ansible.platform collection (AAP-41000) * Fixed default execution environment selection in the automation settings page (AAP-39321) Join the discussion | GCVE Database | 10/28/2025, 21:16:15 UTC Added: 06/02/2026, 21:43:35 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-platform-ui: tar-fs symlink validation bypass (CVE-2025-59343) * python3.11-django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682) * automation-eda-controller: Sensitive Internal Headers Disclosure in AAP EDA Event Streams (CVE-2025-9908) * automation-eda-controller: Event Stream Test Mode Exposes Sensitive Headers in AAP EDA (CVE-2025-9907) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Automation Platform * Fixes issue that prevents SAML and AzureAD authentication when local user accounts share the same email address (AAP-56518) * Updated error handling in the Authenticator form to match other forms in the Platform UI (AAP-56356) * Update autocomplete settings (AAP-55783) * Added a step in the subscription wizard that allows the user to configure automation analytics (AAP-55094) * Subscription credentials can no longer be viewed/edited from the system settings page (AAP-55014) * Fixed the permission list when creating a custom role and selecting the Automation Decisions project or credential types (AAP-54756) * Fixed an issue where the settings did not display "Red Hat" consistently in the API and UI (AAP-54276) * Fixed an issue where the Load More in authentication mapping role dropdown did not work (AAP-54049) * Fixed an issue where the decision environment dropdown displayed an empty dropdown when there are no decision environments available (AAP-53844) * Component label for Platform Auditor role was fixed to display all components (AAP-53551) * Topology layout and full screen mode were fixed (AAP-51106) * Empty strings are no longer displayed in the extra variables field on the Jobs > Details page (AAP-49448) * Added two new toggle options on the subscription wizard to allow for fetching subscriptions using basic authentication (AAP-47865) * Fixed default execution environment selection in the automation settings page (AAP-39321) * automation-gateway has been updated to 2.6.20251022 * automation-gateway-proxy has been updated to 2.6.6-4 * automation-platform-ui has been updated to 2.6.2 * python3.11-django-ansible-base has been updated to 2.6.20251023 Automation controller * The metrics endpoint no longer returns duplicate metrics(AAP-56148) * Fixed Platform Auditor to view controller settings (AAP-55607) * Added support for Red Hat username and password for the subscription management API (AAP-54975) * Fixed system_administrator role creation race condition (AAP-54963) * Improved stability on long-running jobs, clusters under heavy load and network flakiness in receptor (AAP-53742) * Fixed an issue where the ansible.platform collection did not work with the default Red Hat Ansible Automation Platform credential type (AAP-41000) * automation-controller has been updated to 4.7.4 * receptor has been updated to 1.6.0 Automation hub * Fixed an issue where _ui/v2/ user detail displayed the data incorrectly (AAP-54260) * automation-hub has been updated to 4.11.2 * python3.11-galaxy-importer has been updated to 0.4.34 * python3.11-galaxy-ng has been updated to 4.11.2 Event-Driven Ansible * automation-eda-controller has been updated to 1.2.1 Container-based Ansible Automation Platform * Fixed issue with the lightspeed containers configuration when running installation for the second time over the existing AAP (AAP-56263) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55180) * Implemented ansible-core version validation (AAP-54932) * containerized installer setup has been updated to 2.6-2 RPM-based Ansible Automation Platform * Fixed an issue where setting automationgateway_disable_https=false resulted in install failure (AAP-55466) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55183) * Fixed an issue where RESOURCE_KEY SECRET_KEY was not updated when restoring from a different environment (AAP-54942) * Fixed an issue where EDA DE credentials failed to populate on initial install (AAP-54519) * Fixed an issue where automation gateway's envoy.log did not receive logs after it was rotated (AAP-51779) * ansible-automation-platform-installer and installer setup have been updated to 2.6-2 Additional changes * Updated an Join the discussion | GCVE Database | 10/28/2025, 19:18:04 UTC Added: 06/02/2026, 21:43:35 UTC |
0 Red Hat Ansible Automation Platform 2.5 container release includes multiple security fixes addressing vulnerabilities such as an XML External Entity (XXE) issue in langchain-text-splitters, insecure temporary file handling in run-llama/llama_index, potential partial directory traversal via archive extraction, and potential SQL injection in Django QuerySet methods on MySQL and MariaDB. These vulnerabilities affect the container components of the platform and have been addressed in an updated release. Additional bug fixes improve installation stability and API data gathering. Join the discussion | GCVE Database | 10/22/2025, 16:41:24 UTC Added: 06/28/2026, 22:14:08 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * python3.11-django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682) * automation-gateway: tar-fs symlink validation bypass (CVE-2025-59343) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Automation Platform * Azure AD authentication now searches more fields to find the username override field specified. If not found it will log a warning message indicating which fields are valid (AAP-53789) * Support TLSv1.3 on server-to-server requests, where previously services which only supported TLSv1.3 would not work (AAP-49456) * Added a step in the subscription wizard that allows the user to configure automation analytics (AAP-55094) * Subscription credentials can no longer be viewed/edited from the system settings page (AAP-55014) * Fixed an issue where the settings displayed "Red Hat" inconsistently in the API and UI (AAP-54277) * Fixed a bug where platform auditors were not able to see Automation Execution and Platform level settings (AAP-53975) * Fixed an issue where some fields were missing the autocomplete = new-password setting (AAP-53934) * Fixed an issue where AAP could not set/create a playbook when using branch override (AAP-52566) * Empty strings are no longer displayed in the extra variables field on the Jobs > Details page (AAP-49448) * Added two new toggle options on the subscription wizard to allow for fetching subscriptions using basic authentication (AAP-47865) * Fixed validation of prompt-on-launch credentials in a workflow job template (AAP-40540) * Fixed an issue for comments in extra vars sections, all comments in YAML are now persisted on create and edit operations for a resource (AAP-37071) * Updated error handling in the Authenticator form to match other forms in the Platform UI (AAP-22928) * automation-gateway has been updated to 2.5.20251022 * automation-gateway-proxy has been updated to 2.5.10-3 for RHEL8 * automation-gateway-proxy has been updated to 2.6.6-4 for RHEL9 * python3.11-django-ansible-base has been updated to 2.5.20251022 Automation controller * Fixed an issue where the ansible.platform collection did not work with the default Red Hat Ansible Automation Platform credential type (AAP-55685) * Fixed an issue in callback receiver and dispatcher crash loop state caused by re-running the installer with modified inventory hostname (AAP-55638) * Added support for Red Hat username and password for the subscription management API (AAP-54976) * Fixes system_administrator role creation race condition which most commonly happened on new openshift deployments resulting in the default instance group not being created (AAP-54964) * Fixed an issue where Grafana notifications couldn't have an empty dashboard ID or panel ID (AAP-54654) * Improved stability on long-running jobs, clusters under heavy load and network flakiness in receptor (AAP-53742) * Fixed Platform Auditor to view controller settings (AAP-53345) * Added missing instruction to set an environment variable in the CLI in order to achieve compatibility with the current release (AAP-37812) * Fixed Platform Auditor to view Metrics API endpoint (AAP-36492) * automation-controller has been updated to 4.6.21 * receptor has been updated to 1.6.0 Automation hub * Fixed an issue where _ui/v2/ user detail displayed the data correctly (AAP-55957) * automation-hub has been updated to 4.10.9 * python3.11-galaxy-ng has been updated to 4.10.9 * python3.11-galaxy-importer has been updated to 0.4.34 Container-based Ansible Automation Platform * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55181) * Implemented preflight ansible-core version validation (AAP-54931) * Fixed a bug where Ansible would fail to gather the system's UUID for Linux on Power (AAP-54540) * containerized installer setup has been updated to 2.5-20 RPM-based Ansible Automation Platform * Fixed an issue where setting automationgateway_disable_https=false resulted in install failure (AAP-55475) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55184) * Fixed issue where RESOURCE_KEY SECRET_KEY was not updated when restoring from a different environment (AAP-54944) * Fixed issue where EDA DE credentials fa Join the discussion | GCVE Database | 10/22/2025, 13:21:59 UTC Added: 06/02/2026, 21:43:35 UTC |
0 The Cryostat 4 on RHEL 9 container images have been updated to fix several bugs. Users of Cryostat 4 on RHEL 9 container images are advised to upgrade to these updated images, which contain backported patches to fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images. Security Fix(es): * tar-fs: tar-fs symlink validation bypass (CVE-2025-59343) You can find images updated by this advisory in the Red Hat Container Catalog (see the References section). Join the discussion | GCVE Database | 10/06/2025, 13:05:24 UTC Added: 06/02/2026, 21:43:35 UTC |
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory. Join the discussion | CVE Database V5 | 10/01/2025, 00:00:00 UTC Added: 10/01/2025, 18:52:54 UTC |
Showing 1 to 8 of 8 results