CVE-2025-5988

MEDIUM

Ansible aap-gateway - CSRF

Title source: llm

Description

A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 3.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-352
Status draft

Timeline

Published Aug 04, 2025
Tracked Since Feb 18, 2026