VulnerabilityDeferred
CVE-2025-7738
This vulnerability affects administrators or auditors accessing authenticator configurations.
MEDIUM 4.4EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2025:12772
- https://access.redhat.com/security/cve/CVE-2025-7738
- https://bugzilla.redhat.com/show_bug.cgi?id=2381589
- https://github.com/ansible/django-ansible-base/commit/e241ea4dce8df577eda15301e0a8e61be647b27b
- https://github.com/ansible/django-ansible-base/pull/773
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.