Description
A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Any version before 2.5.20250730
0:2.5.20250730-2.el8ap (rpm) before *
0:2.5.20250730-2.el9ap (rpm) before *
Timeline
| 2025-06-11: | Reported to Red Hat. |
| 2025-08-04: | Made public. |
Credits
This issue was discovered by Brennan Paciorek (Red Hat Inc.), Chris Meyers (Red Hat Inc.), Hao Liu (Red Hat Inc.), and Julen Landa Alustiza (Red Hat Inc.).
References
access.redhat.com/errata/RHSA-2025:12772 (RHSA-2025:12772)
access.redhat.com/security/cve/CVE-2025-5988
bugzilla.redhat.com/show_bug.cgi?id=2371644 (RHBZ#2371644)