MEDIUM🇵🇱 Wersja polska

CVE-2025-9909

CVSS 6.7v3.1pub. 2026-02-27upd. 2026-03-25

A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Red Hat Ansible Automation Platform

    APP
    Redhat
    < 2.6
  • Red Hat Ansible Developer

    APP
    Redhat
    1.21.3
  • Red Hat Ansible Inside

    APP
    Redhat
    1.31.4
  • Red Hat Enterprise Linux

    OS
    Redhat
    8.09.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2018-14667CRITICAL9.8⚠ KEVPL ✓same product

RCE przez EL injection w RichFaces Framework 3.X — brak uwierzytelnienia

CVE-2014-7169CRITICAL9.8⚠ KEVPL ✓same product

GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)

CVE-2014-6271CRITICAL9.8⚠ KEVPL ✓same product

ShellShock — RCE poprzez zmienne środowiskowe w GNU Bash