First published: Tue Mar 09 2021(Updated: )
Red Hat Ansible Automation Platform integrates Red Hat's automation suite consisting of Red Hat Ansible Tower, Red Hat Ansible Engine, Automation Hub and use-case specific capabilities for Microsoft Windows, network, security, and more, along with Software-as-a-Service (SaaS)-based capabilities and features for organization-wide effectiveness.<br>This update fixes various bugs and adds enhancements. Documentation for<br>these changes is available from the Release Notes document linked to in the<br>References section.<br>Security Fix(es):<br><li> node-notifier: nodejs-node-notifier: command injection due to the options params not being sanitised when being passed an array (CVE-2020-7789)</li> <li> nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366)</li> <li> django: Potential directory-traversal via archive.extract() (CVE-2021-3281)</li> <li> python-pygments: infinite loop in SML lexer may lead to DoS (CVE-2021-20270)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/automation-hub | <4.2.2-1.el8 | 4.2.2-1.el8 |
redhat/python-bleach | <3.3.0-1.el8 | 3.3.0-1.el8 |
redhat/python-bleach-allowlist | <1.0.3-1.el8 | 1.0.3-1.el8 |
redhat/python-galaxy-importer | <0.2.15-1.el8 | 0.2.15-1.el8 |
redhat/python-galaxy-ng | <4.2.2-1.el8 | 4.2.2-1.el8 |
redhat/python-pulp-ansible | <0.5.6-1.el8 | 0.5.6-1.el8 |
redhat/python3-bleach | <3.3.0-1.el8 | 3.3.0-1.el8 |
redhat/python3-bleach-allowlist | <1.0.3-1.el8 | 1.0.3-1.el8 |
redhat/python3-django | <2.2.18-1.el8 | 2.2.18-1.el8 |
redhat/python3-galaxy-importer | <0.2.15-1.el8 | 0.2.15-1.el8 |
redhat/python3-galaxy-ng | <4.2.2-1.el8 | 4.2.2-1.el8 |
redhat/python3-pulp-ansible | <0.5.6-1.el8 | 0.5.6-1.el8 |
redhat/automation-hub | <4.2.2-1.el7 | 4.2.2-1.el7 |
redhat/python-bleach | <3.3.0-1.el7 | 3.3.0-1.el7 |
redhat/python-bleach-allowlist | <1.0.3-1.el7 | 1.0.3-1.el7 |
redhat/python-galaxy-importer | <0.2.15-1.el7 | 0.2.15-1.el7 |
redhat/python-galaxy-ng | <4.2.2-1.el7 | 4.2.2-1.el7 |
redhat/python-pulp-ansible | <0.5.6-1.el7 | 0.5.6-1.el7 |
redhat/python3-bleach | <3.3.0-1.el7 | 3.3.0-1.el7 |
redhat/python3-bleach-allowlist | <1.0.3-1.el7 | 1.0.3-1.el7 |
redhat/python3-django | <2.2.18-1.el7 | 2.2.18-1.el7 |
redhat/python3-galaxy-importer | <0.2.15-1.el7 | 0.2.15-1.el7 |
redhat/python3-galaxy-ng | <4.2.2-1.el7 | 4.2.2-1.el7 |
redhat/python3-pulp-ansible | <0.5.6-1.el7 | 0.5.6-1.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.