An update is now available for Red Hat Ansible Tower 3.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Ansible Ansible Tower 3.8 security update Advisory ID: RHSA-2022:0482-01 Product: Red Hat Ansible Automation Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:0482 Issue date: 2022-02-08 CVE Names: CVE-2021-4112 ==================================================================== 1. Summary: An update is now available for Red Hat Ansible Tower 3.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Ansible Tower provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Tower makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * Ansible: ansible-tower: Privilege escalation via job isolation escape (CVE-2021-4112) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: This update applies a vulnerability fix to the ansible-towerand ansible-runner rpms. Apply this fix by running the platform installer (setup.sh). 4. Bugs fixed (https://bugzilla.redhat.com/): 2028121 - CVE-2021-4112 ansible-tower: Privilege escalation via job isolation escape 5. References: https://access.redhat.com/security/cve/CVE-2021-4112 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYgNt49zjgjWX9erEAQjZqw//eQ6YrKqyZow9NNcrM+alwtp3uzieNLh3 9r12VCEG85NNhjdGsHqlwbe2dXT0Zy54/Ir3ZCbadA/Ncxgo7ixSVuyBt4ORNQcF 6OFVmWXNCVipbx3VhzpmKISea/HzW9O41FE9U3EWFdpu0MnzLWGM7zEJn898TaL8 bA1nuAnOL++I8KYPnDoFyric0Me9QwI2DI3vvdM3PfFmiZjNVvjhb6zQh18Yd9ws pdye7IOlRYTEc9C3fDBlyw0vcPbPqumMCAm9ao4Ddo16I9UjAEB2tH/4XWPN7KJA Gh/cmePfkrNwMBUze3qFncFaDdPuVqZ3uJQrJU15edIdLqvx+8Lj9o5ktwFX8BMX aTQXhOXvfsUKAdUdZUBgW71KOjmve2VhFK/C6HbCyHI8/Mq8BcU2gXmvPERxDDA/ 1J5qp8rUnbyFEFmXFSN2lMhGXuPVOXXQoJ2brW6iao3PFd3gFS2bx34GhjwK8zEI yDRz6tRbZYWJoTfLR+etgW2ObLoZb31VouzvLJbnIf39F6l5ffqPrJpa1kBczsue 3+E3GEcnxGnMnD2YBwsXDaH3CVGyCAr99p7nyG+ln3+4sPjRN5f6vZUjta/E2jRg +xmdpYK4MHaliHUIrsw+QJZUg0hzqhKDzaLXkMBDYJtt5YKVzTDs6lFfN7UIS/jv Nqarqw2n4BY=NHDx -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat Ansible Tower 3.7.5-1 - RHEL7 Container Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Ansible Tower 3.7.5-1 - Container security and bug fix update Advisory ID: RHSA-2021:0779-01 Product: Red Hat Ansible Tower Advisory URL: https://access.redhat.com/errata/RHSA-2021:0779 Issue date: 2021-03-09 CVE Names: CVE-2019-20372 CVE-2020-10543 CVE-2020-10878 CVE-2020-12723 CVE-2020-35678 CVE-2021-20178 CVE-2021-20180 CVE-2021-20191 CVE-2021-20228 CVE-2021-20253 ==================================================================== 1. Summary: Red Hat Ansible Tower 3.7.5-1 - RHEL7 Container Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Security Fix(es): * Addressed a security issue which can allow a malicious playbook author to elevate to the awx user from outside the isolated environment: CVE-2021-20253 * Upgraded to a more recent version of autobahn to address CVE-2020-35678. * Upgraded to a more recent version of nginx to address CVE-2019-20372. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Fixed a bug which can intermittently cause access to encrypted Tower settings to fail, resulting in failed job launches. * Improved analytics collection to collect the playbook status for all hosts in a playbook run 3.Solution: For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://legacy-controller-docs.ansible.com/ansible-tower/ index.html 4. Bugs fixed (https://bugzilla.redhat.com/): 1790277 - CVE-2019-20372 nginx: HTTP request smuggling in configurations with URL redirect used as error_page 1911314 - CVE-2020-35678 python-autobahn: allows redirect header injection 1928847 - CVE-2021-20253 ansible-tower: Privilege escalation via job isolation escape 5. References: https://access.redhat.com/security/cve/CVE-2019-20372 https://access.redhat.com/security/cve/CVE-2020-10543 https://access.redhat.com/security/cve/CVE-2020-10878 https://access.redhat.com/security/cve/CVE-2020-12723 https://access.redhat.com/security/cve/CVE-2020-35678 https://access.redhat.com/security/cve/CVE-2021-20178 https://access.redhat.com/security/cve/CVE-2021-20180 https://access.redhat.com/security/cve/CVE-2021-20191 https://access.redhat.com/security/cve/CVE-2021-20228 https://access.redhat.com/security/cve/CVE-2021-20253 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYEeZ8tzjgjWX9erEAQj0TA/9Fx0BBmEfw4RU2SpqT9XRlHx3azelKZjL V4jVeQVG5v19MqlH1MdIG+g5bcRQFf96py45ld3yZKShwLc+VcPdgvEZ9jZpbSnl ccl7Q83Gb22AvIQn8UyGzXJ1PQ2EwIzUM24N/OF+VeG11pUaDS90Snsn0BODAgdN I5J/0qn5VOaZhMIQKmwySi+E4oIfHvjRbcu67HB20/JPEizs9/enkcgQRFkr0s77 OoBbj82Q4L/ZmT01oVHdjuSk/tYJy8t1lx9MMgmLE/7hZ6Jei0ut0C/Wl9Oj92jX HaZ1Kpjdq77KEnIJM4YZwW/ib7XxM5GQbqpHeBYMCKbw+1qJli2q8ucQWLNnT6ZR 0U7tBFxRGFYj6hnwGbk+6gart7OD7JZorMTfLQaMhdin3AGsFG46IPyYSugTlQgB ZQkl4my4t3MYuk7/al+s2zrDejx/K1X+mBu8Kjx4sOxV9tsKH/hEh7lbr0s2c2eJ rCkSIQlEKOyc3mUyG4xE8WtFTM+w1BshtuTJjgWxpkRksuaUYixxQDbyDo23//Jq IimdvGuh9cZ4yJFGHyehbW0MbF64yJMmerZpMZhnK2xgZ6idwmeIeAjTd6gcVx7N JbIXgBGeOsCUqokZr0cp4yKY2mhw1J+Qhb9VWC8Rei3UnWNz37gtwCIm88hUmgMj C5QiPiaBTJE=xpAP -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat Ansible Tower 3.6.6-1 - RHEL7 Container 2. Description: * Fixed an XSS vulnerability (CVE-2020-25626) * Fixed the Red Hat sosreport tool to no longer include the Ansible Tower. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: security update - Red Hat Ansible Tower 3.6.6-1 - RHEL7 Container Advisory ID: RHSA-2020:4137-01 Product: Red Hat Ansible Tower Advisory URL: https://access.redhat.com/errata/RHSA-2020:4137 Issue date: 2020-09-30 CVE Names: CVE-2020-14365 CVE-2020-25626 ==================================================================== 1. Summary: Red Hat Ansible Tower 3.6.6-1 - RHEL7 Container 2. Description: * Fixed an XSS vulnerability (CVE-2020-25626) * Fixed the Red Hat sosreport tool to no longer include the Ansible Tower SECRET_KEY value * Fixed the Ansible Tower installer so that it is now compatible with the latest supported Red Hat OpenShift Container Platforms 3.x and 4.x 3. Solution: For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://legacy-controller-docs.ansible.com/ansible-tower/ index.html 4. Bugs fixed (https://bugzilla.redhat.com/): 1878635 - CVE-2020-25626 django-rest-framework: XSS Vulnerability in API viewer 5. References: https://access.redhat.com/security/cve/CVE-2020-14365 https://access.redhat.com/security/cve/CVE-2020-25626 https://access.redhat.com/security/updates/classification/#moderate 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX3STxNzjgjWX9erEAQgzbQ//ekglctyL7PFDT5maarBz05nzh9A02u8a UVrXaEKNnlSAsqGm9M5CP3H1No8IUChq7oqh7NID+jBVN3U8ZqhZcviL9uzD7AFG 0zqkmxaAiZUKCGcEfg0GHxllIXKaRtWFfYFq/OUcDBmVP6pdYgE3fZabFKtuoNdh 0CSPkOE0QzZBz3qST5BLPTVZxa00DocxP1MYgrrRC/uE7qfN5N8Ll1R9rzdhXL19 PHJQkUlgqpl7PJD6Ylh2Om/M36nwf3OOjOLt0YKAdyDjywnUFDObwIEDgp046IvU vnofU8VOShtT4MBCudJn245Dxj1oaN/ZU+RiDcGYcJ1yPixNO7lgfHinxs0XSbfj Z1CvuL7hOOKfu7YWfS7UZZzFXGZzefPrw7rdaTQDL+BOXQmRYh3G7UsgyUOdgIMm yXcJuFPc/j7+8f77lp1qEm1vqQyjfZxLlcnhldLi73KidEjTR1oAMPHm4kYMYG/t FazbOO/2kHNNAGBNcUZS22i0xMRXIPHRSIARsBa36+tVTQflpsYm9TCiMCS8QNFF BqIBBqbUorTyUNJ9dhLoMNlp//+W2MfqCtCW3R/uLgQg31AI8RpOP7sATYRPNO40 FHhsk2V926Quk0JQA1J8AISIelruoBZbwwu+yhUc1NecbPc3Ge856wy4/7XQH0ny PkT1TsyBhYI=Ma/a -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat Ansible Tower 3.7.3-1 - RHEL7 Container 2. Description: * Updated to the latest version of the git-python library to no longer cause certain jobs to fail. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: security update - Red Hat Ansible Tower 3.7.3-1 - RHEL7 Container Advisory ID: RHSA-2020:4136-01 Product: Red Hat Ansible Tower Advisory URL: https://access.redhat.com/errata/RHSA-2020:4136 Issue date: 2020-09-30 CVE Names: CVE-2020-14365 CVE-2020-25626 ==================================================================== 1. Summary: Red Hat Ansible Tower 3.7.3-1 - RHEL7 Container 2. Description: * Updated to the latest version of the git-python library to no longer cause certain jobs to fail * Updated to the latest version of the ovirt.ovirt collection to no longer cause connections to hang when syncing inventory from oVirt/RHV * Added a number of optimizations to Ansible Tower's callback receiver to improve the speed of stdout processing for simultaneous playbooks runs * Added an optional setting to disable the auto-creation of organizations and teams on successful SAML login * Fixed an XSS vulnerability (CVE-2020-25626) * Fixed a slow memory leak in the Daphne process * Fixed Automation Analytics data gathering to no longer fail for customerswith large datasets * Fixed scheduled jobs that run every X minute(s) or hour(s) to no longer fail to run at the proper time * Fixed delays in Ansible Tower's task manager when large numbers of simultaneous jobs are scheduled * Fixed the performance for playbooks that store large amounts of data using the set_stats module * Fixed the awx-manage remove_from_queue tool when used with isolated nodes * Fixed an issue that prevented jobs from being properly marked as canceled when Tower is backed up and then restored to another environment 3. Solution: For information on upgradingAnsible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://legacy-controller-docs.ansible.com/ansible-tower/ index.html 4. Bugs fixed (https://bugzilla.redhat.com/): 1878635 - CVE-2020-25626 django-rest-framework: XSS Vulnerability in API viewer 5. References: https://access.redhat.com/security/cve/CVE-2020-14365 https://access.redhat.com/security/cve/CVE-2020-25626 https://access.redhat.com/security/updates/classification/#moderate 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX3STrNzjgjWX9erEAQjacg//aPaDOirEblGdQwQd+PZEIylBv0mfeaVE M25xAnTJCWpzeC6C8Vd5BKzIsAihNfMjTBGQi6x7b7PrIubd/d3uKYaLsRpsaQHz KQL8gbxuNwWid85HJLvcyh2WRjoW7GAKpvdjh3IjyjTp8c3dkERvjT+LcODE5Mt0 zjUon37FzWZdX4d1heDc3seUtTSpAjskoQ4Dy2qDWC0cyJKSFFqZxWmE/rzBt79r 4niDYCcaEfiiy4lCYqr0qObYvf1hS9sHrD5SVZQYzzfxlL3zNPONUaKwwu1yatcY Sr/o4LdNIUWn04vjxRx6mZNpsJ5+t1Q+YhYGHNtxtE2cy30p+JxpaeJnL50s/VM7 jdQF1/NqcA9F1RKpaquwm3HMPWMvdlzynP5TN+9PdEeT6iCqIXd0Q+scMxGLlhVw zyGU+zlACa9rrSe8DBeS0x3KayydyU7e45mKEJtUHeUYwfPw5rlV/kK05qf7CfMg X7VU6087uU4SAnH5E6Uw8xVibjgAzuSu0GQ/clWdpfiMK85dhdIUGyqYbCOVpFKj /fi0I9N8NAWLItO0OvuWZwjWcOGFQFYw2n+uPo/+Z3XV/oeps4A/KuBrWDnYhvg4 CVzWCpKX//iVaJNWyFwmtitzYRw4couZexR5DdIEABJ2bvydo4gWVQrXNrICLTz3 2v4EqCCyi3U=O51G -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat Ansible Tower 3.6.1-1 - EL7 Container 2. Description: Ansible Tower Version 3.6.1 - -----------------------------. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Critical: Red Hat Ansible Tower 3.6.1-1 - EL7 Container Advisory ID: RHSA-2019:3958-01 Product: Red Hat Ansible Tower Advisory URL: https://access.redhat.com/errata/RHSA-2019:3958 Issue date: 2019-11-25 CVE Names: CVE-2019-14890 ==================================================================== 1. Summary: Red Hat Ansible Tower 3.6.1-1 - EL7 Container 2. Description: Ansible Tower Version 3.6.1 - ----------------------------- - - Fixed accidental disclosure of Red Hat username and password in /api/v2/config (CVE-2019-14890) - - Fixed upgrade failure with bundled installer - - Fixed license check error when reinstalling over a partially-installed Tower - - Fixed database restore when using a PostgreSQL pod - - Fixed error when CA data was missing for a container group credential - - Fixed error when a container group job was launched when Tower was out of capacity - - Fixed a few minor issues in the AWX modules collection 3. Solution: For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://legacy-controller-docs.ansible.com/ansible-tower/ index.html 4. Bugs fixed (https://bugzilla.redhat.com/): 1773622 - CVE-2019-14890 Tower: RHSM username and password exposed after license application 5. References: https://access.redhat.com/security/cve/CVE-2019-14890 https://access.redhat.com/security/updates/classification#critical 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXdvjjdzjgjWX9erEAQj0hA//S4lYJymrZjbMnZ+ONHUqqpG++ot/1C4Q cUKJmrxSGepv6j705PztW3q0d1pTKBI64SGHgBnYNWdvCWsl4Qx5X8OStWv029o/ Aakdqn9CpF7eRbztxRxK+S+pYnRdZ4/5I4quDHuA8uEa0yavFdNUPk/e/XzAvqq3 uHhIv1qESCPf/i7f9ym2RMRdCfwnmsn0jbzxJKL5QnjwU/n9rX9E2skkktH8Y9X4 Sd4LYSHLgR8jBDuXuzGpEgq4MhbZfejyOF7xQ/VgjwqxoJ5Z7Wmv54qPdZ6wS284 klN8a0oduETpoLu5fX6+2EntcvKrZV6Dxj8ldcZ/HeQByN3n0RRTK85BWZxTUZKu wAH24xiqPO4qeXXi0yy2jziLOkO6cgvx2xXSxwR9y1yHNE7B+QClcTiOQF6oIRnR G3t/xQVTxvJypE0Z9+4iTiRbZvGEVdcMWYYj7i7RtfhcCK542ykSdXoUGaIaVO2Y xq3D/njSnI9ZDg5qYpuSbKz9YXjveQxxcASwJP1NIMS8/bX22aVe+xtyU0pupvra 0qYVHVwcgKexoOajYZBMP/shisNn2JyL1xZEFLi8ncncJhhmQzjbLvMNXUp9/zQv OYDYs8Suh8mOqsoJpUyAkOLzgu53kVC6FWx3URU2gaogZ2IrokCp5Dsu8dJag45D NQ+ywpZzoGM=t1tw -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat Ansible Tower 3.3.5 2. Description: For a list of changes included in this release, please read the Ansible Tower Release Notes:. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Ansible Tower 3.3.5 Advisory ID: RHSA-2019:0652-01 Product: Red Hat Ansible Tower Advisory URL: Issue date: 2019-03-26 CVE Names: CVE-2018-5407 CVE-2019-3835 CVE-2019-3838 ==================================================================== 1. Summary: Red Hat Ansible Tower 3.3.5 2. Description: For a list of changes included in this release, please read the Ansible Tower Release Notes: https://legacy-controller-docs.ansible.com/ansible-tower/ 3. Solution: For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://legacy-controller-docs.ansible.com/ansible-tower/ index.html 4. References: https://access.redhat.com/security/cve/CVE-2018-5407 https://access.redhat.com/security/cve/CVE-2019-3835 https://access.redhat.com/security/cve/CVE-2019-3838 https://access.redhat.com/security/updates/classification#moderate 5. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXJpWH9zjgjWX9erEAQg9NA//ebBrxCt3FFeYOU1qUTzEpjdQOEdOLWLK hxtz2zn/r6eanzbJkFuRkNFJKw5LzCS5oA1ByPh3x+TauVzb0cEmat6EGNNt4RAc tl7f7ELlpo8L9lwleVIPNUf7Qh5dKvKmAlmvXcuAKWZBOVe12ezwgjAAMEfiDc1U p/RfC3C8HMltjZ9f6VoEBj6+LEaEU7xXUIGzNEZa5CrEb6CHc6zKnt2MHDy6TjAT YuG6JxhhqoeHVkI2s7dARTzu4Wt7S3o9dATVXORa8mrDBSPlw+DPsGZwqNRO1ucj mlBXNnk3DStV8zmI08Au7BaxRLtprGf6zpXDAD8qhACdOKjWYAZu4QNIR+1Bdr2s QbhN3uGi0XgqJF/UYbuGzgcc9SoWW/NJvTg67eIwA/TrMbK40MR/J3rqvS9K5hjT AP56WDFYZSXzwcW8jrQ77a+smQQGrbTjMtvVQukWfaDGm/A8EENIhxewS2DLJp7D pVbupNTL94EGEpLdHQ7EUkdNtehanW8aSaOjeXIk6GBcVbRcTX8qjKeisi+x5w+y LnXeSZrPmbjMH75l1vY1o/3Aap2aoazGA3/hFBABw6fJR6ucXBNvPXTlVuLbm/cj v5AAVrvjeHCbKCh85bPOHyba2N2uNF3e3MWEuLozgexI1IKdyIGCD8TKbFlpf+oz EfZHY++p974=qMcC -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.