An update is now available for Red Hat Ansible Automation Platform 2.4 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update Advisory ID: RHSA-2023:5208-01 Product: Red Hat Ansible Automation Platform Advisory URL: https://access.redhat.com/errata/RHSA-2023:5208 Issue date: 2023-09-18 CVE Names: CVE-2023-41164 ===================================================================== 1. Summary: An update is now available for Red Hat Ansible Automation Platform 2.4 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Ansible Automation Platform 2.4 for RHEL 8 - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Ansible Automation Platform 2.4 for RHEL 9 - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * python3-django/python39-django: Potentialdenial of service vulnerability in django.utils.encoding.uri_to_iri() (CVE-2023-41164) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional changes: * ansible-core has been updated to 2.15.4 (AAP-16010) * ansible-runner has been updated to 2.3.4 (AAP-15594) * automation-controller has been updated to 4.4.4 (AAP-15594) * python3-django/python39-django has been updated to 3.2.21 (AAP-15704) Updates and fixes for automation controller: * Fixed job error handling so that we correctly report error text from ansible-runner or receptor in cases we previously showed "Job terminated due to error" (AAP-12917) * The constructed inventory edit form no longer hangs indefinitely in the loading state for users with edit permissions (AAP-15099) * Added views for a monthly summary of host metrics (AAP-15677) * Added host metrics to exported analytics data (AAP-15677) * Introduced a periodic task and management command for cleaning up old host metrics (AAP-15677) * Fixed bug where rapidly clicking on launch button in preview step would launch multiple jobs (AAP-15689) * Fixed incorrect capacity for remote execution nodes when resource limits are set in OpenShift (AAP-15736) 4. Solution: Red Hat Ansible Automation Platform 5. Bugs fixed (https://bugzilla.redhat.com/): 2237258 - CVE-2023-41164 python-django: Potential denial of service vulnerability in ``django.utils.encoding.uri_to_iri()`` 6. Package List: Red Hat Ansible Automation Platform 2.4 for RHEL8: Source: ansible-core-2.15.4-1.el8ap.src.rpm ansible-runner-2.3.4-1.el8ap.src.rpm automation-controller-4.4.4-1.el8ap.src.rpm python3x-django-3.2.21-1.el8ap.src.rpm aarch64: automation-controller-4.4.4-1.el8ap.aarch64.rpm automation-controller-venv-tower-4.4.4-1.el8ap.aarch64.rpm noarch: ansible-core-2.15.4-1.el8ap.noarch.rpm ansible-runner-2.3.4-1.el8ap.noarch.rpm ansible-test-2.15.4-1.el8ap.noarch.rpm automation-controller-cli-4.4.4-1.el8ap.noarch.rpm automation-controller-server-4.4.4-1.el8ap.noarch.rpm automation-controller-ui-4.4.4-1.el8ap.noarch.rpm python39-ansible-runner-2.3.4-1.el8ap.noarch.rpm python39-django-3.2.21-1.el8ap.noarch.rpm ppc64le: automation-controller-4.4.4-1.el8ap.ppc64le.rpm automation-controller-venv-tower-4.4.4-1.el8ap.ppc64le.rpm s390x: automation-controller-4.4.4-1.el8ap.s390x.rpm automation-controller-venv-tower-4.4.4-1.el8ap.s390x.rpm x86_64: automation-controller-4.4.4-1.el8ap.x86_64.rpm automation-controller-venv-tower-4.4.4-1.el8ap.x86_64.rpm Red Hat Ansible Automation Platform 2.4 for RHEL 8: Source: ansible-core-2.15.4-1.el8ap.src.rpm ansible-runner-2.3.4-1.el8ap.src.rpm noarch: ansible-core-2.15.4-1.el8ap.noarch.rpm ansible-runner-2.3.4-1.el8ap.noarch.rpm python39-ansible-runner-2.3.4-1.el8ap.noarch.rpm Red Hat Ansible Automation Platform 2.4 for RHEL 8: Source: ansible-core-2.15.4-1.el8ap.src.rpm ansible-runner-2.3.4-1.el8ap.src.rpm noarch: ansible-core-2.15.4-1.el8ap.noarch.rpm ansible-runner-2.3.4-1.el8ap.noarch.rpm python39-ansible-runner-2.3.4-1.el8ap.noarch.rpm Red Hat Ansible Automation Platform 2.4 for RHEL9: Source: ansible-core-2.15.4-1.el9ap.src.rpm ansible-runner-2.3.4-1.el9ap.src.rpm automation-controller-4.4.4-1.el9ap.src.rpm python-django-3.2.21-1.el9ap.src.rpm aarch64: automation-controller-4.4.4-1.el9ap.aarch64.rpm automation-controller-venv-tower-4.4.4-1.el9ap.aarch64.rpm noarch: ansible-core-2.15.4-1.el9ap.noarch.rpm ansible-runner-2.3.4-1.el9ap.noarch.rpm ansible-test-2.15.4-1.el9ap.noarch.rpm automation-controller-cli-4.4.4-1.el9ap.noarch.rpm automation-controller-server-4.4.4-1.el9ap.noarch.rpm automation-controller-ui-4.4.4-1.el9ap.noarch.rpm python3-ansible-runner-2.3.4-1.el9ap.noarch.rpm python3-django-3.2.21-1.el9ap.noarch.rpm ppc64le: automation-controller-4.4.4-1.el9ap.ppc64le.rpm automation-controller-venv-tower-4.4.4-1.el9ap.ppc64le.rpm s390x: automation-controller-4.4.4-1.el9ap.s390x.rpm automation-controller-venv-tower-4.4.4-1.el9ap.s390x.rpm x86_64: automation-controller-4.4.4-1.el9ap.x86_64.rpm automation-controller-venv-tower-4.4.4-1.el9ap.x86_64.rpm Red Hat Ansible Automation Platform 2.4 for RHEL 9: Source: ansible-core-2.15.4-1.el9ap.src.rpm ansible-runner-2.3.4-1.el9ap.src.rpm noarch: ansible-core-2.15.4-1.el9ap.noarch.rpm ansible-runner-2.3.4-1.el9ap.noarch.rpm python3-ansible-runner-2.3.4-1.el9ap.noarch.rpm Red Hat Ansible Automation Platform 2.4 for RHEL 9: Source: ansible-core-2.15.4-1.el9ap.src.rpm ansible-runner-2.3.4-1.el9ap.src.rpm noarch: ansible-core-2.15.4-1.el9ap.noarch.rpm ansible-runner-2.3.4-1.el9ap.noarch.rpm python3-ansible-runner-2.3.4-1.el9ap.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-41164 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlCMDBAAoJENzjgjWX9erEnBcP/iQ8KGcnfBTqdsQCJ6I1gWfd QJHuH+RbneS4q675tybTZhtAf1QTGnBBVH6VtEA10nj4EnkUG74zn1RfgKiUL7Wa As6b0FTvv5VK5wWB0IkkZNitJSKo3bMLorCwhBKtDAFSrftojzpHZdn4e3J3f0Vp CCi4MCgKShuTnWXPNhGhBQWfUodtUJ/shIgcnmtDcYwAQDV6h9vgE5Mr6eATqd++ aB8GHhfxw7UFRG3O60WTtz+zfzzl/2IeGIhpnIgnZDbiiw4+OLI14sj4sV02C28z aZjgi3z6BlLQ7MqPFE3aw5wdQv1pzywf38UWY6rGf5wEKA5o9buEO8emlN9+kY11 j2hbtNWwd9kOBJV0QEVGD1SpjymtvaQxpirDcHKHUH6bT5n9cwUFU18KEFetEDgZ opsgFnqYK5b7kj2dXPliB1yKiH09NpZMAbP+ETJ8vh0dkNkpWQWeNaVAR9NfWmeK Wjbi1n7dniMy8jPc3kB1viFxdwnXh71ubTPT/fejaphuTUrkMsNQyDz0DVA7m7Tl GjEhzkI4ypGtFgphForTquekKTvjQY5iPGKs4etkjBcxeQJzN0MJ4ojs3KOcHhXL X9vAJW2tjjduaaC332C0ApdGO2TjmFI7ZiX9iw2ERd6ChgOrYp40CjnpzpZV4Mx5 91s+FbpesEX2H2zQc/bD =5ac+ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat Ansible Automation Platform 2.3 Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Low: Red Hat Ansible Automation Platform 2.3 Product Security and Bug Fix Update Advisory ID: RHSA-2023:4991-01 Product: Red Hat Ansible Automation Platform Advisory URL: https://access.redhat.com/errata/RHSA-2023:4991 Issue date: 2023-09-06 CVE Names: CVE-2023-40267 ===================================================================== 1. Summary: An update is now available for Red Hat Ansible Automation Platform 2.3 Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Ansible Automation Platform 2.3 for RHEL 8 - x86_64 Red Hat Ansible Automation Platform 2.3 for RHEL 9 - x86_64 3. Description: Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: GitPython: Insecure non-multi options in clone and clone_from is not blocked (CVE-2023-40267) Formore details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional changes: * ansible-core has been updated to 2.14.9 (AAP-15270) * automation-controller has been updated to 4.3.13 (AAP-15548) * automation controller: Fix bug that can cause a deadlock on shutdown when redis is unavailable. (AAP-14217) 4. Solution: Red Hat Ansible Automation Platform 5. Bugs fixed (https://bugzilla.redhat.com/): 2231474 - CVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from is not blocked 6. Package List: Red Hat Ansible Automation Platform 2.3 for RHEL 8: Source: ansible-core-2.14.9-1.el8ap.src.rpm automation-controller-4.3.13-1.el8ap.src.rpm x86_64: ansible-core-2.14.9-1.el8ap.x86_64.rpm ansible-test-2.14.9-1.el8ap.x86_64.rpm automation-controller-4.3.13-1.el8ap.x86_64.rpm automation-controller-cli-4.3.13-1.el8ap.x86_64.rpm automation-controller-server-4.3.13-1.el8ap.x86_64.rpm automation-controller-ui-4.3.13-1.el8ap.x86_64.rpm automation-controller-venv-tower-4.3.13-1.el8ap.x86_64.rpm Red Hat Ansible Automation Platform 2.3 for RHEL 8: Source: ansible-core-2.14.9-1.el8ap.src.rpm x86_64: ansible-core-2.14.9-1.el8ap.x86_64.rpm Red Hat Ansible Automation Platform 2.3 for RHEL 8: Source: ansible-core-2.14.9-1.el8ap.src.rpm x86_64: ansible-core-2.14.9-1.el8ap.x86_64.rpm Red Hat Ansible Automation Platform 2.3 for RHEL 8: Source: ansible-core-2.14.9-1.el8ap.src.rpm x86_64: ansible-core-2.14.9-1.el8ap.x86_64.rpm Red Hat Ansible Automation Platform 2.3 for RHEL9: Source: ansible-core-2.14.9-1.el9ap.src.rpm automation-controller-4.3.13-1.el9ap.src.rpm x86_64: ansible-core-2.14.9-1.el9ap.x86_64.rpm ansible-test-2.14.9-1.el9ap.x86_64.rpm automation-controller-4.3.13-1.el9ap.x86_64.rpm automation-controller-cli-4.3.13-1.el9ap.x86_64.rpm automation-controller-server-4.3.13-1.el9ap.x86_64.rpm automation-controller-ui-4.3.13-1.el9ap.x86_64.rpm automation-controller-venv-tower-4.3.13-1.el9ap.x86_64.rpm Red Hat Ansible Automation Platform 2.3 for RHEL 9: Source: ansible-core-2.14.9-1.el9ap.src.rpm x86_64: ansible-core-2.14.9-1.el9ap.x86_64.rpm Red Hat Ansible Automation Platform 2.3 for RHEL 9: Source: ansible-core-2.14.9-1.el9ap.src.rpm x86_64: ansible-core-2.14.9-1.el9ap.x86_64.rpm Red Hat Ansible Automation Platform 2.3 for RHEL 9: Source: ansible-core-2.14.9-1.el9ap.src.rpm x86_64: ansible-core-2.14.9-1.el9ap.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-40267 https://access.redhat.com/security/updates/classification/#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJk+M4JAAoJENzjgjWX9erEsLkQAIva1tmZHlZWhD+C7c2QDiJw b38rDl0T1ltvk+cG/FQ+471pANMromvRalKsvymnwk92WgnOP7BXGFCA04ZLus0I rLu9pyqPSOcMHzLWoJsXd+0W2ViEx54kqQUFBomIK7ThDmaiqG9eeJY1//b+4+Q2 0Pv5ho2Ig6MNvJv8t9DXJ+GSWRvb2q0CzDRxH1KOORrCqVWpP8oslOJPt+HFzJ+p zzvg6IsxNKdQXunnjLHyXkqWfIdTtJppjh6tdUTsANx85COlFYH2Bz2X5rqPq0bH PM07TuUWyoG3obYnvapubqs4w55iykObxiYC1jXXB4VnIMZTah/ZsZDDAa9c3Y+F q3QAhASYf7E74i14QRgkvp85IJdxg3FoKjX5npQXZ1UpQ/sZy7ZXNqyC4d/aVw2M iQGGMbsHQycMZGPySYzL0UjUmcmjLTMZh/obSmk3qV6S1Q0JcngU3LfxMB+IRs0E yzENXxzOUq6lnMpabTR71Na9enmWcmIPDyJUJZp21bk0usXgO7s7T3Ivrc7ZAwPt GFu6Kkgann1AjjMD73J8Xoh7HbOv37OWa+/oDFKerml1rai+mSKpcPtCJMZEeHs5 3QnOCr2utXBDPB4kKffBZup9DkayHQbrBcicNNLAMj6lP1P7uXf6mOUjnLhskWTv hADRKnSL1tPp3u0zE7yH =jKDd -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat Ansible Automation Platform 2.3 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Ansible Automation Platform 2.3 Product Security and Bug Fix Update Advisory ID: RHSA-2023:4470-01 Product: Red Hat Ansible Automation Platform Advisory URL: https://access.redhat.com/errata/RHSA-2023:4470 Issue date: 2023-08-03 CVE Names: CVE-2022-41717 CVE-2022-41724 CVE-2022-41725 CVE-2023-24534 CVE-2023-24536 CVE-2023-24537 CVE-2023-24538 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400 ===================================================================== 1. Summary: An update is now available for Red Hat Ansible Automation Platform 2.3 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Ansible Automation Platform 2.3 for RHEL 8 - x86_64 3. Description: Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, andagentless language. Security Fix(es) for openshift-clients: * golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) * golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724) * golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725) * golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534) * golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536) * golang: go/parser: Infinite loop in parsing (CVE-2023-24537) * golang: html/template: backticks not treated as string delimiters (CVE-2023-24538) * golang: html/template: improper sanitization of CSS values (CVE-2023-24539) * golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540) * golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2161274 - CVE-2022-41717 golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests 2178488 - CVE-2022-41725 golang: net/http, mime/multipart: denial of service from excessive resource consumption 2178492 - CVE-2022-41724 golang: crypto/tls: large handshake records may cause panics 2184481 - CVE-2023-24538 golang: html/template: backticks not treated as string delimiters 2184482 - CVE-2023-24536 golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption 2184483 - CVE-2023-24534 golang: net/http, net/textproto: denial of service fromexcessive memory allocation 2184484 - CVE-2023-24537 golang: go/parser: Infinite loop in parsing 2196026 - CVE-2023-24539 golang: html/template: improper sanitization of CSS values 2196027 - CVE-2023-24540 golang: html/template: improper handling of JavaScript whitespace 2196029 - CVE-2023-29400 golang: html/template: improper handling of empty HTML attributes 6. Package List: Red Hat Ansible Automation Platform 2.3 for RHEL 8: Source: openshift-clients-4.12.0-202307200611.p0.g49844f7.assembly.stream.el8.src.rpm x86_64: openshift-clients-4.12.0-202307200611.p0.g49844f7.assembly.stream.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-41717 https://access.redhat.com/security/cve/CVE-2022-41724 https://access.redhat.com/security/cve/CVE-2022-41725 https://access.redhat.com/security/cve/CVE-2023-24534 https://access.redhat.com/security/cve/CVE-2023-24536 https://access.redhat.com/security/cve/CVE-2023-24537 https://access.redhat.com/security/cve/CVE-2023-24538 https://access.redhat.com/security/cve/CVE-2023-24539 https://access.redhat.com/security/cve/CVE-2023-24540 https://access.redhat.com/security/cve/CVE-2023-29400 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJky7g3AAoJENzjgjWX9erEhHsP/RcbV8pZf6odMQDBYsVdnV0L dVZRW12HjfDorWo0BNer1oPSOPCCMbNziPNEzvWb5ij4putbPlNJTNbgvbt/GCe4 L3wRiPjcSPXaTJ3SjrueT3u6oWxN6FA9H/vYUYyHd98tAHUbTf3GtZvLDVokMs75 rHmmvivyBgCXXLQyGfNvjGEd1RIyuiJMjan/aWG1ZNL90REYo3gMSxsgeHofLjYB xe9oBJx+v1mfoWAfZQK4b8bNMMY7Ao0YxUyUcmKHHfVq93og1S+peF+HlCaSNCMH VYqtVJTZAPqj4J7oImkTF2aObsIb5dmSYjtwdQWI+Et6SKVm6xkIlM2cZUKqjjW/ ZuXXv9ACb8oqWwQHaQqYxrZPN7wUIWL5AAa6uNjZWr9SsYyQgdYDJ3WzvjdKvSsq yIqqPf5Gtfqu/ORe1lli8TrVZyvCG/HVVy/LPy0TnMyW0mA0PmJuxAHb6uAkA0k3 vUljuhez3kUslP/NJiWUzX4k2Q2q8m+ur3Mm8Z5r39qZ3uSWllTBCq3G/1iJfeGx 5W2F8oyKXfnRS/l38xgKkbeAA4KQTo6Y5/JTA0ybUiuPsVDnKZ5vCwIVEMsH8/Uo AZ7TemczNaY9d6wCtzgFTwKFJG8IpZoN55p4nS8Jc8665HYLzwrfrtq/eIyhg/iB 873U4d/+ykPVwFsSGYCe =37Iu -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat Ansible Automation Platform 2.1 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Ansible Automation Platform 2.1.3 security and bug fix update Advisory ID: RHSA-2022:6078-01 Product: Red Hat Ansible Automation Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:6078 Issue date: 2022-08-16 CVE Names: CVE-2022-2568 ==================================================================== 1. Summary: An update is now available for Red Hat Ansible Automation Platform 2.1 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Ansible Automation Platform 2.1 for RHEL 8 - noarch, x86_64 3. Description: Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation hub: Ansible: Logic flaw leads to privilege escalation (CVE-2022-2568) For more details about the security issue(s), including the impact, a CVSS score,acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: Red Hat Ansible Automation Platform 5. Bugs fixed (https://bugzilla.redhat.com/): 2108653 - CVE-2022-2568 Ansible: Logic flaw leads to privilage escalation 6. Package List: Red Hat Ansible Automation Platform 2.1 for RHEL 8: Source: ansible-core-2.12.7-2.el8ap.src.rpm automation-controller-4.1.3-2.el8ap.src.rpm automation-hub-4.4.4-1.el8pc.src.rpm openshift-clients-4.10.0-202206211856.p0.g45460a5.assembly.stream.el8.src.rpm pulpcore-selinux-1.3.2-1.el8ap.src.rpm python-galaxy-ng-4.4.4-1.el8pc.src.rpm noarch: automation-hub-4.4.4-1.el8pc.noarch.rpm python38-galaxy-ng-4.4.4-1.el8pc.noarch.rpm x86_64: ansible-core-2.12.7-2.el8ap.x86_64.rpm ansible-test-2.12.7-2.el8ap.x86_64.rpm automation-controller-4.1.3-2.el8ap.x86_64.rpm automation-controller-cli-4.1.3-2.el8ap.x86_64.rpm automation-controller-server-4.1.3-2.el8ap.x86_64.rpm automation-controller-ui-4.1.3-2.el8ap.x86_64.rpm automation-controller-venv-tower-4.1.3-2.el8ap.x86_64.rpm openshift-clients-4.10.0-202206211856.p0.g45460a5.assembly.stream.el8.x86_64.rpm pulpcore-selinux-1.3.2-1.el8ap.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-2568 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYvvcw9zjgjWX9erEAQhftg//ZcvK3pw707V96oGX81QkfgeGK+xgtK7r x4TJuf0N7yyJKe/kaHnlwZYApifJvaBLpCJCWB2hArr5pqN56bBOcBO8IK5zMx72 DH5z9PXFmv46Plo+YYIZqYHgCk7QE+g8GyBTnQ1GRiEIGdM74r2O65o+GGd5Z8KU 0NoDnIuMWWKqF9gT9Iefab9Klbk9mpl3huDCb6F5jFrhk9fGXuXLoPkYy6HLdp0j Qncd7vXidsX5TTGkdHUMgHjrMEoJhYtautRdHb/fqgfTinVx2Q6iLW925DRvbDXb Qsm+AIVlKTemEMfvqZXzWIVv2kyg5/rRbe8BhmxoGSJFx4QQb6gZ16AcWWyW7oxg KzEDJAbow4KMCeqq7ZmR7yNRKRbknXYJozosR0HNmBqIi4Icq/+tv8+1pRCUq3np WBB1w8QvM+Cm9WQx2Ro610s+JMi9TlOhWh79ntev9jM5kxQ22jz6I9w+WLzFS+GU nTv8ipfgcLshnOk83mHn0sQua8IS+JRRoxnc8iorhVFCVCWdaQ7dlg8gDKs1sgH4 Lg/wwbXxxOf8XowafKejSAdsrXVFC2dvn4QhB+U0PjCXOZe4SyXQRcyBjs9tvH57 rGGg3oS/ekPE4J10oA3D5h9GKyoRDs1rHv0CBM2MYkByV7XS8v+VfahOfiUW6aYo bQzB5GNJ8e0=auJC -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat Ansible Automation Platform 2.2 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Ansible Automation Platform 2.2.0 Product Security Update Advisory ID: RHSA-2022:6079-01 Product: Red Hat Ansible Automation Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:6079 Issue date: 2022-08-16 CVE Names: CVE-2022-2568 ==================================================================== 1. Summary: An update is now available for Red Hat Ansible Automation Platform 2.2 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Ansible Automation Platform 2.2 for RHEL 8 - noarch Red Hat Ansible Automation Platform 2.2 for RHEL 9 - noarch 3. Description: Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation hub: Ansible: Logic flaw leads to privilege escalation (CVE-2022-2568) For more details about the securityissue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2108653 - CVE-2022-2568 Ansible: Logic flaw leads to privilage escalation 6. Package List: Red Hat Ansible Automation Platform 2.2 for RHEL 8: Source: python3x-galaxy-ng-4.5.0-4.el8ap.src.rpm noarch: python39-galaxy-ng-4.5.0-4.el8ap.noarch.rpm Red Hat Ansible Automation Platform 2.2 for RHEL 9: Source: python-galaxy-ng-4.5.0-4.el9ap.src.rpm noarch: python3-galaxy-ng-4.5.0-4.el9ap.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-2568 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYvvcudzjgjWX9erEAQhaNBAAhoOJXPMIykWVx3OANchJRJ1AtpO78fbr OmhT938VvjhjLe46hcrYPDlFzxeTPrbsGrAtGsCiZlo8LWmQtVNYLjG1wrL0362Z KLFrx6bmaEqosmPJ6IpONQomebrwH/2OFI+6V+U/glRT/Q/fVFWRlfeuh4btMdDY qvxcpnafLqYd2ZIvOQgZ8IoCviW6VbeCYfkdXAhaVCy8BX+q2dXcLb+wfIgQ6xRD JqKbskbw5mCF+zkrl/fnBu6Y3b/BLY7VNQ1X3biFil9TWUMMaPWL3hFiabpM+U4P heHnId1h2Mv9rBtOxwYKnp9P9jmXjyARLIiRDYoUMcxIG/WTzr1LIwKW7UAFOEjD y1/LOLe8TsgIrsisrfuCFnK0l/04jwaViKcKuJD5hurnGeFeIG4pWyDPk9fDbLY7 XXlLxZIxq147gk1knhxLgZF64hM6BMuAFRW5eVP7KJtN89OTZe/cDSIw7+jBuW63 IuPoRDLD6+9FDLFu+lDQusZdysx4+GRxutsbvKYvYSyhD9zi2GQL9soDQUT7P+wf nRPvWN/2NWaIu3h8vfBdhO3zWTyfDSJq+xQwYpN1lPfTman9cC6XI+aVZU4W9YQy sFhaEofylPpkrXjV+Z4ryPHOIq2ppCfjJ7ourjH5VJSpHfVd2+JVzL+1vZFOcawN 74OeazUqo8o=kUNg -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat Automation Platform 1.2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Automation Platform 1.2.5 security and bugfixes update Advisory ID: RHSA-2021:3473-01 Product: Red Hat Ansible Automation Platform Advisory URL: https://access.redhat.com/errata/RHSA-2021:3473 Issue date: 2021-09-08 CVE Names: CVE-2021-33503 ==================================================================== 1. Summary: An update is now available for Red Hat Automation Platform 1.2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Automation Hub 4.2 for RHEL 7 - noarch, x86_64 Red Hat Automation Hub 4.2 for RHEL 8 - noarch, x86_64 3. Description: Red Hat Ansible Automation Platform integrates Red Hat’s automation suite consisting of Red Hat Ansible Tower, Red Hat Ansible Engine, and use-case specific capabilities for Microsoft Windows,network, security, and more, along with Software-as-a-Service (SaaS)-based capabilities and features for organization-wide effectiveness. Security Fix(es): * python-urllib3: Catastrophic backtracking in URL authority parser (CVE-2021-33503) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: This update fixes various bugs and addsenhancements. Documentation for these changes is available from the Release Notes document linked to in the References section. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1968074 - CVE-2021-33503 python-urllib3: ReDoS in the parsing of authority part of URL 6. Package List: Red Hat Automation Hub 4.2 for RHEL 7: Source: automation-hub-4.2.6-1.el7pc.src.rpm python-galaxy-ng-4.2.6-1.el7pc.src.rpm python-requests-2.25.1-1.el7pc.src.rpm python-urllib3-1.26.5-1.el7pc.src.rpm python3-click-7.1.2-3.el7pc.src.rpm noarch: automation-hub-4.2.6-1.el7pc.noarch.rpm python3-chardet-3.0.4-3.el7pc.noarch.rpm python3-click-7.1.2-3.el7pc.noarch.rpm python3-galaxy-ng-4.2.6-1.el7pc.noarch.rpm python3-gnupg-0.4.6-3.el7pc.noarch.rpm python3-jinja2-2.11.2-3.el7pc.noarch.rpm python3-requests-2.25.1-1.el7pc.noarch.rpm python3-semantic-version-2.8.5-3.el7pc.noarch.rpm python3-urllib3-1.26.5-1.el7pc.noarch.rpm x86_64: python3-markupsafe-1.1.1-4.el7pc.x86_64.rpm python3-markupsafe-debuginfo-1.1.1-4.el7pc.x86_64.rpm Red Hat Automation Hub 4.2 for RHEL 8: Source: automation-hub-4.2.6-1.el8pc.src.rpm python-galaxy-ng-4.2.6-1.el8pc.src.rpm python-requests-2.25.1-1.el8pc.src.rpm python-urllib3-1.26.5-1.el8pc.src.rpm noarch: automation-hub-4.2.6-1.el8pc.noarch.rpm python3-click-7.1.2-3.el8pc.noarch.rpm python3-galaxy-ng-4.2.6-1.el8pc.noarch.rpm python3-gnupg-0.4.6-3.el8pc.noarch.rpm python3-jinja2-2.11.2-3.el8pc.noarch.rpm python3-requests-2.25.1-1.el8pc.noarch.rpm python3-semantic-version-2.8.5-3.el8pc.noarch.rpm python3-urllib3-1.26.5-1.el8pc.noarch.rpm x86_64: python3-markupsafe-1.1.1-4.el8pc.x86_64.rpm python3-markupsafe-debuginfo-1.1.1-4.el8pc.x86_64.rpm python3-markupsafe-debugsource-1.1.1-4.el8pc.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify thesignature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-33503 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_ansible_automation_platform/1.2/html/red_hat_ansible_automation_platform_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYTkOENzjgjWX9erEAQgkkg/9HPbXh5Y2kqE3bD9OmEMjXc4bTTqzVXVO oDM3TQw6jNs8opP9IU5l3u9GlbPVsqVHnmRc8iN4WhWC7i2HqQV4ycu0BQq5LMrd DPzTY6I8RNjkmmTIXauPsDda0AqW+AaBm7JJGB2YMxHJ4YAO+nMo1iptmqBRStoX 4fnmX9NED4uPz3hv+fhXDai84OewX70CPxadcog3Q4+dIAuHclunBn6ErDtQgEGl 40NqbNFgDcv0MQ/gSO2H7OJQLFuTsIdk0uJxx8J0sHPLLRqdKlwdoYEox744VxZ5 RpKVTt7AEiAUuQxRLSgoTLm2wpqw/BlkjHkWLlFfs+u+hiPe6esB7nEl1MLiGC+T hr5i70BEp2MNhi0QGkY3CRsb9+e1KKtsrIO8fThypnfMGxO+qw66rA73Dosj7eRM 8bmfdYR5WQepYD0+Pmpa04IkheF3j93uqD1DLxc0TtsO5wmO2tzlrUuJyepXpiOD IQIzDxtVPZqfO8e9V563vIYXsRnaQUqID0vzG09MIutx9cOwugbRV/BI2DsSiK7V X1v/ehZz7ybXYYkLRYtg6RRGIX3hUi0Yw0ijbh18qd4XrBhzDaYDDsnBIctWOyrN gbENWxoRIlfLIRG5m+bNCh1WoviBdt9bP0YS+Jtx48GcQIDMJQpa/U3t73r9h6hc IF9mKVY3M2Y=7nq3 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat Ansible Automation Platform Resource Operator 1.2 (technical preview) images that fix several security issues. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Ansible Automation Platform Operator 1.2 security update Advisory ID: RHSA-2021:1079-01 Product: Red Hat Ansible Automation Platform Advisory URL: https://access.redhat.com/errata/RHSA-2021:1079 Issue date: 2021-04-06 Keywords: Security Update CVE Names: CVE-2017-12652 CVE-2018-20843 CVE-2019-5094 CVE-2019-5188 CVE-2019-11719 CVE-2019-11727 CVE-2019-11756 CVE-2019-12749 CVE-2019-14866 CVE-2019-14973 CVE-2019-15903 CVE-2019-17006 CVE-2019-17023 CVE-2019-17498 CVE-2019-17546 CVE-2019-19956 CVE-2019-20388 CVE-2019-20907 CVE-2020-1971 CVE-2020-5313 CVE-2020-6829 CVE-2020-7595 CVE-2020-8177 CVE-2020-8625 CVE-2020-12243 CVE-2020-12400 CVE-2020-12401 CVE-2020-12402 CVE-2020-12403 CVE-2020-14422 CVE-2020-15999 CVE-2021-3156 CVE-2021-3447 CVE-2021-20178 CVE-2021-20180 CVE-2021-20191 CVE-2021-20228 ==================================================================== 1. Summary: Red Hat Ansible Automation Platform Resource Operator 1.2 (technical preview) images that fix several security issues. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2.Description: Red Hat Ansible Automation Platform Resource Operator container images with security fixes. Ansible Automation Platform manages Ansible Platform jobs and workflows that can interface with any infrastructure on a Red Hat OpenShift Container Platform cluster, or on a traditional infrastructure that is running off-cluster. Security fixes: CVE-2021-20191 ansible: multiple modules expose secured values [ansible_automation_platform-1.2] (BZ#1916813) CVE-2021-20178 ansible: user data leak in snmp_facts module [ansible_automation_platform-1.2] (BZ#1914774) CVE-2021-20180 ansible: ansible module: bitbucket_pipeline_variable exposes secured values [ansible_automation_platform-1.2] (BZ#1915808) CVE-2021-20228 ansible: basic.py no_log with fallback option [ansible_automation_platform-1.2] (BZ#1925002) CVE-2021-3447 ansible: multiple modules expose secured values [ansible_automation_platform-1.2] (BZ#1939349) For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 1914774 - CVE-2021-20178 ansible: user data leak in snmp_facts module 1915808 - CVE-2021-20180 ansible module: bitbucket_pipeline_variable exposes secured values 1916813 - CVE-2021-20191 ansible: multiple modules expose secured values 1925002 - CVE-2021-20228 ansible: basic.py no_log with fallback option 1939349 - CVE-2021-3447 ansible: multiple modules expose secured values 5.References: https://access.redhat.com/security/cve/CVE-2017-12652 https://access.redhat.com/security/cve/CVE-2018-20843 https://access.redhat.com/security/cve/CVE-2019-5094 https://access.redhat.com/security/cve/CVE-2019-5188 https://access.redhat.com/security/cve/CVE-2019-11719 https://access.redhat.com/security/cve/CVE-2019-11727 https://access.redhat.com/security/cve/CVE-2019-11756 https://access.redhat.com/security/cve/CVE-2019-12749 https://access.redhat.com/security/cve/CVE-2019-14866 https://access.redhat.com/security/cve/CVE-2019-14973 https://access.redhat.com/security/cve/CVE-2019-15903 https://access.redhat.com/security/cve/CVE-2019-17006 https://access.redhat.com/security/cve/CVE-2019-17023 https://access.redhat.com/security/cve/CVE-2019-17498 https://access.redhat.com/security/cve/CVE-2019-17546 https://access.redhat.com/security/cve/CVE-2019-19956 https://access.redhat.com/security/cve/CVE-2019-20388 https://access.redhat.com/security/cve/CVE-2019-20907 https://access.redhat.com/security/cve/CVE-2020-1971 https://access.redhat.com/security/cve/CVE-2020-5313 https://access.redhat.com/security/cve/CVE-2020-6829 https://access.redhat.com/security/cve/CVE-2020-7595 https://access.redhat.com/security/cve/CVE-2020-8177 https://access.redhat.com/security/cve/CVE-2020-8625 https://access.redhat.com/security/cve/CVE-2020-12243 https://access.redhat.com/security/cve/CVE-2020-12400 https://access.redhat.com/security/cve/CVE-2020-12401 https://access.redhat.com/security/cve/CVE-2020-12402 https://access.redhat.com/security/cve/CVE-2020-12403 https://access.redhat.com/security/cve/CVE-2020-14422 https://access.redhat.com/security/cve/CVE-2020-15999 https://access.redhat.com/security/cve/CVE-2021-3156 https://access.redhat.com/security/cve/CVE-2021-3447 https://access.redhat.com/security/cve/CVE-2021-20178 https://access.redhat.com/security/cve/CVE-2021-20180 https://access.redhat.com/security/cve/CVE-2021-20191 https://access.redhat.com/security/cve/CVE-2021-20228 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/cve/CVE-2021-20191 https://access.redhat.com/security/cve/CVE-2021-20178 https://access.redhat.com/security/cve/CVE-2021-20180 https://access.redhat.com/security/cve/CVE-2021-20228 https://access.redhat.com/security/cve/CVE-2021-3447 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYHBeatzjgjWX9erEAQhLuw//QLV4QWc4E9o8cG3IJr3xIt6b/OHs6b9s hp04e5kT7IWFpmR3VXK+BEK2dd+NiGdvXPOpwe4BaOUWEDmq+dx4Vac5Z0GcZJUK AJz8dXFPYBgIafuIkWyY9UIvSO/VsQ2Dr4+KUnB1obALAz3ndSoQJFS1hysFBXHS +MulKiYVwFw7UbfvGuFLjmLrNTAflVa9MHmdh3P53bU+U2mCgzuHTFIpodkZhuIt aIR0H/dgHXXG8co20Zb5Nciqr0CxqejQ+xz84Yu0I+y1LWdBAhi34c3zJY4rlEQS 6/nfcsSPEadNCTXQu/TX6yvo6sE8A7/xGh1PDf0PLVv+Xh7TE53MtmTnYcl8uiRO 9m3CfJ7PLO2hpl6QuJzuUe7nXx65/qIoKQjZfNpZVXj/LQtL1F4RE7szmswIGNZL IG51pYEUE98aR3gIlLpoMjW4vtC+rdcwSBaLW5gH1Q5hNRlTLmFBTKmYNkCpd4Ho NP3AKEwx9R8ZdGYcCuZwYPvSQSqX+B9qURw5G4E/vbso8Vh9RYQ3kusnf93Q/1LG ImHCbsVWJDMMt/NRj5OvqgZc18ROqHhSpuJ+A44VCI+UihkZb2ai4DjGef0WHZhq XTMyLECTJIwM4aY+BC1ohYm0Whvs/w/hd03tGFBJhlIoBYakY6o8lRD7hCc8E/YI dEQ0aSabgEY=D/Lt -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.