A sensitive information disclosure vulnerability exists in the Gateway API of Ansible Automation Platform. When fetching the configuration of certain authenticators (GitHub Enterprise or GitHub Enterprise Org), the API returns the OAuth2 client secret in clear text instead of redacting or masking it (e.g., returning $encrypted$). This flaw is present in the endpoint /api/gateway/v1/authenticators/<authenticator ID>/ and can be reproduced by administrators or auditors with access. While not directly exploitable over the network by unauthorized actors, it exposes a high-value secret that could be misused if accessed by a malicious insider or compromised privileged account.
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.5 for RHEL 9 Red Hat Ansible Automation Platform 2.5 for RHEL 8 Via RHSA-2025:12772 https://access.redhat.com/errata/RHSA-2025:12772