A flaw was found in the Ansible Automation Platform. The Event-Driven Ansible server exposes the WebSocket JSON web token (JWT) when running Rulebook activations in debug mode, which, if obtained by an attacker, can be used to connect to the socket and issue commands that return Playbook content or other sensitive data.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in the Ansible Automation Platform. The Event-Driven Ansible server exposes the WebSocket JSON web token (JWT) when running Rulebook activations in debug mode, which, if obtained by an attacker, can be used to connect to the socket and issue commands that return Playbook content or other sensitive data. | |
Title | ansible-automation-platform: EDA server exposes websocket jwt when running rulebook activations in debug mode | |
Weaknesses | CWE-1258 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

No data.

No data.

No data.
