RHSA-2024:1057
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Systems
- redhat•ansible-automation-platform-installer
< 0:2.4-6.el8ap | < 0:2.4-6.el9ap
- redhat•ansible-rulebook
< 0:1.0.5-1.el8ap | < 0:1.0.5-1.el9ap
- redhat•automation-eda-controller
< 0:1.0.5-1.el8ap | < 0:1.0.5-1.el9ap
- redhat•automation-eda-controller-server
< 0:1.0.5-1.el8ap | < 0:1.0.5-1.el9ap
- redhat•automation-eda-controller-ui
< 0:1.0.5-1.el8ap | < 0:1.0.5-1.el9ap
- redhat•python-aiohttp
< 0:3.9.1-1.el9ap
- redhat•python-aiohttp-debugsource
< 0:3.9.1-1.el9ap
- redhat•python-django
< 0:4.2.10-1.el9ap
- redhat•python-jinja2
< 0:3.1.3-1.el9ap
- redhat•python-pillow
< 0:10.0.1-1.el9ap
- redhat•python-pillow-debugsource
< 0:10.0.1-1.el9ap
- redhat•python-pycryptodomex
< 0:3.20.0-1.el9ap
- redhat•python-pycryptodomex-debugsource
< 0:3.20.0-1.el9ap
- redhat•python-pygments
< 0:2.17.2-1.el9ap
- redhat•python3-aiohttp
< 0:3.9.1-1.el9ap
- redhat•python3-aiohttp-debuginfo
< 0:3.9.1-1.el9ap
- redhat•python3-django
< 0:4.2.10-1.el9ap
- redhat•python3-jinja2
< 0:3.1.3-1.el9ap
- redhat•python3-pillow
< 0:10.0.1-1.el9ap
- redhat•python3-pillow-debuginfo
< 0:10.0.1-1.el9ap
- redhat•python3-pycryptodomex
< 0:3.20.0-1.el9ap
- redhat•python3-pycryptodomex-debuginfo
< 0:3.20.0-1.el9ap
- redhat•python3-pygments
< 0:2.17.2-1.el9ap
- redhat•python39-aiohttp
< 0:3.9.1-1.el8ap
- redhat•python39-aiohttp-debuginfo
< 0:3.9.1-1.el8ap
- redhat•python39-django
< 0:4.2.10-1.el8ap
- redhat•python39-jinja2
< 0:3.1.3-1.el8ap
- redhat•python39-pillow
< 0:10.0.1-1.el8ap
- redhat•python39-pillow-debuginfo
< 0:10.0.1-1.el8ap
- redhat•python39-pycryptodomex
< 0:3.20.0-1.el8ap
- redhat•python39-pycryptodomex-debuginfo
< 0:3.20.0-1.el8ap
- redhat•python39-pygments
< 0:2.17.2-1.el8ap
- redhat•python3x-aiohttp
< 0:3.9.1-1.el8ap
- redhat•python3x-aiohttp-debugsource
< 0:3.9.1-1.el8ap
- redhat•python3x-django
< 0:4.2.10-1.el8ap
- redhat•python3x-jinja2
< 0:3.1.3-1.el8ap
- redhat•python3x-pillow
< 0:10.0.1-1.el8ap
- redhat•python3x-pillow-debugsource
< 0:10.0.1-1.el8ap
- redhat•python3x-pycryptodomex
< 0:3.20.0-1.el8ap
- redhat•python3x-pycryptodomex-debugsource
< 0:3.20.0-1.el8ap
- redhat•python3x-pygments
< 0:2.17.2-1.el8ap
References (50)
- https://access.redhat.com/errata/RHSA-2024:1057
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2247820
- https://bugzilla.redhat.com/show_bug.cgi?id=2249825
- https://bugzilla.redhat.com/show_bug.cgi?id=2251643
- https://bugzilla.redhat.com/show_bug.cgi?id=2252235
- https://bugzilla.redhat.com/show_bug.cgi?id=2252248
- https://bugzilla.redhat.com/show_bug.cgi?id=2257028
- https://bugzilla.redhat.com/show_bug.cgi?id=2257854
- https://bugzilla.redhat.com/show_bug.cgi?id=2261856
- https://bugzilla.redhat.com/show_bug.cgi?id=2265085
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1057.json
- https://access.redhat.com/security/cve/CVE-2022-40896
- https://www.cve.org/CVERecord?id=CVE-2022-40896
- https://nvd.nist.gov/vuln/detail/CVE-2022-40896
- https://access.redhat.com/security/cve/CVE-2023-44271
- https://www.cve.org/CVERecord?id=CVE-2023-44271
- https://nvd.nist.gov/vuln/detail/CVE-2023-44271
- https://devhub.checkmarx.com/cve-details/CVE-2023-44271/
- https://github.com/python-pillow/Pillow/pull/7244
- https://access.redhat.com/security/cve/CVE-2023-47627
- https://www.cve.org/CVERecord?id=CVE-2023-47627
- https://nvd.nist.gov/vuln/detail/CVE-2023-47627
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-gfw2-4jvh-wgfg
- https://access.redhat.com/security/cve/CVE-2023-49081
- https://www.cve.org/CVERecord?id=CVE-2023-49081
- https://nvd.nist.gov/vuln/detail/CVE-2023-49081
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-q3qx-c6g2-7pw2
- https://access.redhat.com/security/cve/CVE-2023-49082
- https://www.cve.org/CVERecord?id=CVE-2023-49082
- https://nvd.nist.gov/vuln/detail/CVE-2023-49082
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-qvrw-v9rv-5rjx
- https://access.redhat.com/security/cve/CVE-2023-52323
- https://www.cve.org/CVERecord?id=CVE-2023-52323
- https://nvd.nist.gov/vuln/detail/CVE-2023-52323
- https://github.com/Legrandin/pycryptodome/blob/master/Changelog.rst
- https://pypi.org/project/pycryptodomex/#history
- https://access.redhat.com/security/cve/CVE-2024-1657
- https://www.cve.org/CVERecord?id=CVE-2024-1657
- https://nvd.nist.gov/vuln/detail/CVE-2024-1657
- https://access.redhat.com/security/cve/CVE-2024-22195
- https://www.cve.org/CVERecord?id=CVE-2024-22195
- https://nvd.nist.gov/vuln/detail/CVE-2024-22195
- https://github.com/pallets/jinja/releases/tag/3.1.3
- https://github.com/pallets/jinja/security/advisories/GHSA-h5c8-rqwp-cp95
- https://access.redhat.com/security/cve/CVE-2024-24680
- https://www.cve.org/CVERecord?id=CVE-2024-24680
- https://nvd.nist.gov/vuln/detail/CVE-2024-24680
- https://github.com/advisories/GHSA-xxj9-f6rv-m3x4
- https://www.djangoproject.com/weblog/2024/feb/06/security-releases/