A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.
References
Configurations
No configuration.
History
05 Aug 2025, 14:34
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
04 Aug 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Aug 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-04 16:15
Updated : 2025-08-05 14:34
NVD link : CVE-2025-5988
Mitre link : CVE-2025-5988
CVE.ORG link : CVE-2025-5988
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)