Lucene search

K
redhatRedHatRHSA-2024:4522
HistoryJul 12, 2024 - 1:15 a.m.

(RHSA-2024:4522) Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update

2024-07-1201:15:48
access.redhat.com
8
red hat
ansible automation
it automation
security fix
bug fix
cve-2024-34064
cve-2024-28102
cve-2024-35195
updates
automation controller
aap-26398
aap-25136
aap-25115
aap-24543
4.5.8
aap-metrics-utility
0.3.0
ansible-core
2.15.12

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

AI Score

7.2

Confidence

High

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language.

Security Fix(es):

  • automation-controller: jinja2: accepts keys containing non-attribute characters (CVE-2024-34064)
  • automation-controller: jwcrypto: malicious JWE token can cause denial of service (CVE-2024-28102)
  • automation-controller: requests: subsequent requests to the same host ignore cert verification (CVE-2024-35195)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updates and fixes for automation controller:

  • Fixed a bug where the controller does not respect β€œDATABASES[β€˜OPTIONS’]” setting, if specified (AAP-26398)
  • Changed all uses of β€œImplicitRoleField” to perform an β€œon_delete=SET_NULL” (AAP-25136)
  • Fixed the HostMetric automated counter to display the correct values (AAP-25115)
  • Added Django logout redirects (AAP-24543)
  • automation-controller has been updated to 4.5.8

Additional changes:

  • aap-metrics-utility has been updated to 0.3.0 (AAP-25875)
  • ansible-core has been updated to 2.15.12 (AAP-25536)

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

AI Score

7.2

Confidence

High