CVE-2025-5988
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
04/08/2025
Last modified:
05/08/2025
Description
A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM



