RHSA-2025:0340: Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Other sources
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language.<br>Security Fix(es):<br><li> automation-controller: Potential SQL injection in HasKey(lhs, rhs) on Oracle (CVE-2024-53908)</li> <li> automation-controller: Potential denial-of-service in django.utils.html.striptags() (CVE-2024-53907)</li> <li> automation-controller: Denial of Service through Data corruption in gRPC-C++ (CVE-2024-11407)</li> <li> automation-gateway: nanoid mishandles non-integer values (CVE-2024-55565)</li> <li> python3.11-aio<a href="http:" target="blank">http:</a> aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions (CVE-2024-52304)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Updates and fixes included:<br>Platform<br><li> Fixed 'not found' error that occurred occasionally when navigating form wizards (AAP-37495)</li> <li> Fixed an issue where IDKEY attribute was improperly used to determine the username field in social auth pipelines (AAP-38300)</li> <li> Fixed an issue where the X-DAB-JW-TOKEN header message would flood logs (AAP-38169)</li> <li> Fixed an issue where authenticator could create a userid and return a non-viable authenticatoruid (AAP-38021)</li> <li> Enhanced the status API, /api/gateway/v1/status/, from the services property within the JSON to an array (AAP-37903)</li> <li> Fixes an issue where a private key was displayed in plain text when downloading the OpenAPI schema file. NOTE: This was not the private key used by gateway, just a random default key (AAP-37843)</li> Automation controller<br><li> Added 'joblifecycle' as a choice in loggers to send externally and added 'organizationid' field to logs related to a job (AAP-37537)</li> <li> Fixed date comparison mismatch for traceback from 'hostmetricsummarymonthly' task (AAP-37487)</li> <li> Fixed scheduled jobs with count set to a non-zero value to no longer run unexpectedly (AAP-37290)</li> <li> Fixed the POST operation to '/api/controller/login/' via gateway to no longer result in a fatal error (AAP-37235)</li> <li> Fixed the behavior of the project's 'requirements.yml' to no longer revert to a prior state in a cluster (AAP-37228)</li> <li> Fixed occasional error while creating event partition table before starting a job, when lots of jobs are launched quickly (AAP-37227)</li> <li> Fixed the named URL to no longer return a 404 error code while launching a job template (AAP-37025)</li> <li> Updated receptor to clean up temporary receptor files after a job completes on nodes (AAP-36904)</li> <li> Fixed the POST operation to '/api/controller/login/' via gateway to no longer result in a fatal error (AAP-33911)</li> <li> automation-controller has been updated to 4.6.6</li> Container-based Ansible Automation Platform<br><li> Fixed an issue where the provided inventory file sample for growth inventories could cause the installation to stall on low resource systems (AAP-38372)</li> <li> Fixed an issue where the throttle capacity of controller in growth topology installation would allow for performance degradation (AAP-38207)</li> <li> Fixed an issue where the receptor TLS certificate content was not validated during the preflight role execution ensuring that the x509 Subject Alt Name (SAN) field contains the required ISO Object Identifier (OID) (AAP-37880)</li> <li> TLS certificate and key files are now validated during the preflight role execution (AAP-37845)</li> <li> Fixed an issue where the Postgresql SSL mode variables were not validated during the preflight role execution (AAP-37352)</li> <li> containerized installer setup has been updated to 2.5-8</li> RPM-based Ansible Automation Platform<br><li> Fixed an issue where adding a new automation hub host to upgraded environment has caused the installation to fail (AAP-38204)</li> <li> Fixed an issue where the link to the documents in the installer README.md was broken (AAP-37627)</li> <li> Updated nginx configuration to properly return API status for Event-Driven Ansible event stream service (AAP-32816)</li> <li> ansible-automation-platform-installer and installer setup have been updated to 2.5-7</li> Additional changes:<br><li> Installing ansible-core no longer installs python3-jmespath on RHEL 8 (AAP-18251)</li> <li> ansible-core has been updated to 2.16.14-2</li> <li> automation-gateway has been updated to 2.5.20250115</li> <li> python3.11-aiohttp has been updated to 3.10.11 along with its dependencies</li> <li> python3.11-django-ansible-base has been updated to 2.5.20250115</li> <li> python3.11-galaxy-importer has been updated to 0.4.27</li> <li> python3.11-pulpcore has been updated to 3.49.29</li>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:0340?
The severity of RHSA-2025:0340 is categorized as Important.
How do I fix RHSA-2025:0340?
To fix RHSA-2025:0340, update the affected packages to the specified versions, such as 2.5-7.el9a for ansible-automation-platform-installer.
What products are affected by RHSA-2025:0340?
Affected products for RHSA-2025:0340 include Red Hat Ansible Automation Platform and Red Hat Ansible Developer.
When was RHSA-2025:0340 released?
RHSA-2025:0340 was released to address security vulnerabilities in the affected packages.
What is the main focus of RHSA-2025:0340?
The main focus of RHSA-2025:0340 is to provide security and bug fix updates for Red Hat Ansible Automation Platform.