Threats Tagged 'cve-2025-62707'
View all threats tagged with 'cve-2025-62707'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-62707'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Update(s) and Fix(es): * Fixes issue that prevents SAML and AzureAD authentication when local user accounts share the same email address (AAP-56518) * Updated error handling in the Authenticator form to match other forms in the Platform UI. API errors for specific fields are correctly mapped to the form fields in the UI (AAP-56356) * Fixed issue with the lightspeed containers configuration when running installation for the second time over the existing AAP (AAP-56263) * Changes in the deployment and nginx configuration now allow for gunicorn and daphne to bind to :: as well, essentially allowing for seamlessly binding to IPv4 and IPv6 (dual-stack) addresses, while also enabling the operator to run in single-stack IPv6 or IPv4 scenarios (AAP-56192) * Update autocomplete settings (AAP-55783) * Fix an issue when restoring an upgraded AAP environment from 2.4 (AAP-55648) * Fixed a bug where the user could set an image without the respective version, causing the installation to enter an error loop (AAP-55642) * Fixed a bug that caused a failure to gather the job data from the controller API (AAP-55632) * Address the duplication issue by adding labels (AAP-55621) * Fixed Platform Auditor to view controller settings (AAP-55607) * Fixed an issue where setting automationgateway_disable_https=false resulted in install failure (AAP-55466) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55183) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55180) * Added a step in the subscription wizard that allows the user to configure automation analytics (AAP-55094) * Added postgres_extra_settings to AAP operators to apply postgresql configuration file level changes to managed postgres (AAP-55053) * Subscription credentials can no longer be viewed/edited from the system settings page (AAP-55014) * Add support for Red Hat username and password for the subscription management API (AAP-54975) * Fixes system_administrator role creation race condition which most commonly happened on new openshift deployments resulting in the default instance group not being created (AAP-54963) * Fixed issue where RESOURCE_KEY SECRET_KEY was not updated when restoring from a different environment (AAP-54942) * Updated ansible-builder and ansible-navigator to use EE images from ansible-automation-platform-26 namespace by default (AAP-54934) * Fix the permission list when creating a custom role and selecting the Automation Decisions project or credential types (AAP-54756) * Settings display "Red Hat" consistently in the API and UI (AAP-54276) * Fix _ui/v2/ user detail displays data correctly (AAP-54260) * Fix Ansible Lightspeed API version during AAP idle (AAP-54174) * Fix error in lightspeed service when upgrading from AAP 2.5 to AAP 2.6 (AAP-54064) * Fix "Load More" in Authentication Mapping Role dropdown doesn't work (AAP-54049) * Replaced dropdown type for decision environments on the rulebook activation form so that when there are no decision environments available, dropdown displays "No results found" instead of an empty dropdown (AAP-53844) * This version of receptor addresses improves stability on long-running jobs, clusters under heavy load and network flakiness (AAP-53742) * Axios package version was updated (AAP-53718) * Component label for Platform Auditor role was fixed to display all components (AAP-53551) * Fixed an issue where automation gateway's envoy.log did not receive logs after it was rotated (AAP-51779) * Topology layout and full screen mode were fixed (AAP-51106) * Empty strings are no longer displayed in the extra variables field on the Jobs > Details page (AAP-49448) * Added two new toggle options on the subscription wizard to allow for fetching subscriptions using basic authentication (AAP-47865) * Controller Red Hat Ansible Automation Platform now works with ansible.platform collection (AAP-41000) * Fixed default execution environment selection in the automation settings page (AAP-39321) Join the discussion | GCVE Database | 10/28/2025, 21:16:15 UTC Added: 06/02/2026, 21:43:35 UTC |
0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-platform-ui: tar-fs symlink validation bypass (CVE-2025-59343) * python3.11-django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682) * automation-eda-controller: Sensitive Internal Headers Disclosure in AAP EDA Event Streams (CVE-2025-9908) * automation-eda-controller: Event Stream Test Mode Exposes Sensitive Headers in AAP EDA (CVE-2025-9907) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Automation Platform * Fixes issue that prevents SAML and AzureAD authentication when local user accounts share the same email address (AAP-56518) * Updated error handling in the Authenticator form to match other forms in the Platform UI (AAP-56356) * Update autocomplete settings (AAP-55783) * Added a step in the subscription wizard that allows the user to configure automation analytics (AAP-55094) * Subscription credentials can no longer be viewed/edited from the system settings page (AAP-55014) * Fixed the permission list when creating a custom role and selecting the Automation Decisions project or credential types (AAP-54756) * Fixed an issue where the settings did not display "Red Hat" consistently in the API and UI (AAP-54276) * Fixed an issue where the Load More in authentication mapping role dropdown did not work (AAP-54049) * Fixed an issue where the decision environment dropdown displayed an empty dropdown when there are no decision environments available (AAP-53844) * Component label for Platform Auditor role was fixed to display all components (AAP-53551) * Topology layout and full screen mode were fixed (AAP-51106) * Empty strings are no longer displayed in the extra variables field on the Jobs > Details page (AAP-49448) * Added two new toggle options on the subscription wizard to allow for fetching subscriptions using basic authentication (AAP-47865) * Fixed default execution environment selection in the automation settings page (AAP-39321) * automation-gateway has been updated to 2.6.20251022 * automation-gateway-proxy has been updated to 2.6.6-4 * automation-platform-ui has been updated to 2.6.2 * python3.11-django-ansible-base has been updated to 2.6.20251023 Automation controller * The metrics endpoint no longer returns duplicate metrics(AAP-56148) * Fixed Platform Auditor to view controller settings (AAP-55607) * Added support for Red Hat username and password for the subscription management API (AAP-54975) * Fixed system_administrator role creation race condition (AAP-54963) * Improved stability on long-running jobs, clusters under heavy load and network flakiness in receptor (AAP-53742) * Fixed an issue where the ansible.platform collection did not work with the default Red Hat Ansible Automation Platform credential type (AAP-41000) * automation-controller has been updated to 4.7.4 * receptor has been updated to 1.6.0 Automation hub * Fixed an issue where _ui/v2/ user detail displayed the data incorrectly (AAP-54260) * automation-hub has been updated to 4.11.2 * python3.11-galaxy-importer has been updated to 0.4.34 * python3.11-galaxy-ng has been updated to 4.11.2 Event-Driven Ansible * automation-eda-controller has been updated to 1.2.1 Container-based Ansible Automation Platform * Fixed issue with the lightspeed containers configuration when running installation for the second time over the existing AAP (AAP-56263) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55180) * Implemented ansible-core version validation (AAP-54932) * containerized installer setup has been updated to 2.6-2 RPM-based Ansible Automation Platform * Fixed an issue where setting automationgateway_disable_https=false resulted in install failure (AAP-55466) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55183) * Fixed an issue where RESOURCE_KEY SECRET_KEY was not updated when restoring from a different environment (AAP-54942) * Fixed an issue where EDA DE credentials failed to populate on initial install (AAP-54519) * Fixed an issue where automation gateway's envoy.log did not receive logs after it was rotated (AAP-51779) * ansible-automation-platform-installer and installer setup have been updated to 2.6-2 Additional changes * Updated an Join the discussion | GCVE Database | 10/28/2025, 19:18:04 UTC Added: 06/02/2026, 21:43:35 UTC |
0 pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter. This has been fixed in pypdf version 6.1.3. Join the discussion | CVE Database V5 | 10/22/2025, 21:36:32 UTC Added: 10/22/2025, 21:56:16 UTC |
Showing 1 to 3 of 3 results