Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2025-57847

CVE-2025-57847: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium6.4

    Medium [CVE-2025-57847] privilege escalation via excessive group writable /etc/passwd permissions

    CVE-2025-57847Source published Source updated

    A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container. Red Hat Product Security has rated this vulnerability as moderate severity for affected products which run on OpenShift. The vulnerability allows for potential privilege escalation within a container, but OpenShift's default, multi-layered…

    Affected products in this advisory
    • Red Hat Ansible Automation Platform 2.5
    • Red Hat Ansible Automation Platform Ansible Core 2
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • ansible-automation-platform-25/ee-minimal-rhel8:1784035663
    • ansible-automation-platform-25/ee-minimal-rhel9:1784051694
    • RHSA-2026:42144
    • RHSA-2026:42141
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery