CVE-2025-57847
CVE-2025-57847: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium6.4
Medium [CVE-2025-57847] privilege escalation via excessive group writable /etc/passwd permissions
CVE-2025-57847Source published Source updated
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container. Red Hat Product Security has rated this vulnerability as moderate severity for affected products which run on OpenShift. The vulnerability allows for potential privilege escalation within a container, but OpenShift's default, multi-layered…
- Affected products in this advisory
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform Ansible Core 2
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- ansible-automation-platform-25/ee-minimal-rhel8:1784035663
- ansible-automation-platform-25/ee-minimal-rhel9:1784051694
- RHSA-2026:42144
- RHSA-2026:42141
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.