CVE-2025-1801: Aap-gateway: aap-gateway privilege escalation
A flaw was found in aap-gateway. Concurrent requests handled by the gateway grpc service can result in "swapping" a request. Effectively, a lesser privileged user (even unauthenticated) can get the JWT of a greater privileged user
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1801?
CVE-2025-1801 is classified as a high severity vulnerability due to the potential for unauthorized access to privileged user information.
How do I fix CVE-2025-1801?
To mitigate CVE-2025-1801, ensure you apply the latest patch or update provided for the Ansible aap-gateway software.
Who is affected by CVE-2025-1801?
CVE-2025-1801 affects users of the Ansible aap-gateway, particularly those using it for managing concurrent requests.
What are the consequences of CVE-2025-1801?
The consequences of CVE-2025-1801 include potential privilege escalation, as lower privileged users may gain access to higher privileged users' JWT tokens.
When was CVE-2025-1801 disclosed?
CVE-2025-1801 was disclosed in 2025, highlighting a significant security flaw in handling requests within the Ansible aap-gateway.