RHSA-2025:0340: Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update

Published Jan 15, 2025
·
Updated

Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update

Other sources

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language.<br>Security Fix(es):<br><li> automation-controller: Potential SQL injection in HasKey(lhs, rhs) on Oracle (CVE-2024-53908)</li> <li> automation-controller: Potential denial-of-service in django.utils.html.striptags() (CVE-2024-53907)</li> <li> automation-controller: Denial of Service through Data corruption in gRPC-C++ (CVE-2024-11407)</li> <li> automation-gateway: nanoid mishandles non-integer values (CVE-2024-55565)</li> <li> python3.11-aio<a href="http:" target="blank">http:</a> aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions (CVE-2024-52304)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Updates and fixes included:<br>Platform<br><li> Fixed 'not found' error that occurred occasionally when navigating form wizards (AAP-37495)</li> <li> Fixed an issue where IDKEY attribute was improperly used to determine the username field in social auth pipelines (AAP-38300)</li> <li> Fixed an issue where the X-DAB-JW-TOKEN header message would flood logs (AAP-38169)</li> <li> Fixed an issue where authenticator could create a userid and return a non-viable authenticatoruid (AAP-38021)</li> <li> Enhanced the status API, /api/gateway/v1/status/, from the services property within the JSON to an array (AAP-37903)</li> <li> Fixes an issue where a private key was displayed in plain text when downloading the OpenAPI schema file. NOTE: This was not the private key used by gateway, just a random default key (AAP-37843)</li> Automation controller<br><li> Added 'joblifecycle' as a choice in loggers to send externally and added 'organizationid' field to logs related to a job (AAP-37537)</li> <li> Fixed date comparison mismatch for traceback from 'hostmetricsummarymonthly' task (AAP-37487)</li> <li> Fixed scheduled jobs with count set to a non-zero value to no longer run unexpectedly (AAP-37290)</li> <li> Fixed the POST operation to '/api/controller/login/' via gateway to no longer result in a fatal error (AAP-37235)</li> <li> Fixed the behavior of the project's 'requirements.yml' to no longer revert to a prior state in a cluster (AAP-37228)</li> <li> Fixed occasional error while creating event partition table before starting a job, when lots of jobs are launched quickly (AAP-37227)</li> <li> Fixed the named URL to no longer return a 404 error code while launching a job template (AAP-37025)</li> <li> Updated receptor to clean up temporary receptor files after a job completes on nodes (AAP-36904)</li> <li> Fixed the POST operation to '/api/controller/login/' via gateway to no longer result in a fatal error (AAP-33911)</li> <li> automation-controller has been updated to 4.6.6</li> Container-based Ansible Automation Platform<br><li> Fixed an issue where the provided inventory file sample for growth inventories could cause the installation to stall on low resource systems (AAP-38372)</li> <li> Fixed an issue where the throttle capacity of controller in growth topology installation would allow for performance degradation (AAP-38207)</li> <li> Fixed an issue where the receptor TLS certificate content was not validated during the preflight role execution ensuring that the x509 Subject Alt Name (SAN) field contains the required ISO Object Identifier (OID) (AAP-37880)</li> <li> TLS certificate and key files are now validated during the preflight role execution (AAP-37845)</li> <li> Fixed an issue where the Postgresql SSL mode variables were not validated during the preflight role execution (AAP-37352)</li> <li> containerized installer setup has been updated to 2.5-8</li> RPM-based Ansible Automation Platform<br><li> Fixed an issue where adding a new automation hub host to upgraded environment has caused the installation to fail (AAP-38204)</li> <li> Fixed an issue where the link to the documents in the installer README.md was broken (AAP-37627)</li> <li> Updated nginx configuration to properly return API status for Event-Driven Ansible event stream service (AAP-32816)</li> <li> ansible-automation-platform-installer and installer setup have been updated to 2.5-7</li> Additional changes:<br><li> Installing ansible-core no longer installs python3-jmespath on RHEL 8 (AAP-18251)</li> <li> ansible-core has been updated to 2.16.14-2</li> <li> automation-gateway has been updated to 2.5.20250115</li> <li> python3.11-aiohttp has been updated to 3.10.11 along with its dependencies</li> <li> python3.11-django-ansible-base has been updated to 2.5.20250115</li> <li> python3.11-galaxy-importer has been updated to 0.4.27</li> <li> python3.11-pulpcore has been updated to 3.49.29</li>

Red Hat

Affected Software

47 affected componentsFixes available
Red Hat Red Hat Ansible Inside
Red Hat Red Hat Ansible Automation Platform
Red Hat Red Hat Ansible Developer
redhat/ansible-automation-platform-installer<2.5-7.el9a
2.5-7.el9a
redhat/ansible-core<2.16.14-2.el9a
2.16.14-2.el9a
redhat/automation-controller<4.6.6-1.el9a
4.6.6-1.el9a
redhat/automation-gateway<2.5.20250115-1.el9a
2.5.20250115-1.el9a
redhat/python3.11-aiodns<3.2.0-1.el9a
3.2.0-1.el9a
redhat/python3.11-aiohappyeyeballs<2.4.4-1.el9a
2.4.4-1.el9a
redhat/python3.11-aiohttp<3.10.11-1.el9a
3.10.11-1.el9a
redhat/python3.11-django-ansible-base<2.5.20250115-1.el9a
2.5.20250115-1.el9a
redhat/python3.11-galaxy-importer<0.4.27-1.el9a
0.4.27-1.el9a
redhat/python3.11-pulpcore<3.49.29-1.el9a
3.49.29-1.el9a
redhat/python3.11-yarl<1.13.1-1.el9a
1.13.1-1.el9a
redhat/ansible-test<2.16.14-2.el9a
2.16.14-2.el9a
redhat/automation-controller-cli<4.6.6-1.el9a
4.6.6-1.el9a
redhat/automation-controller-server<4.6.6-1.el9a
4.6.6-1.el9a
redhat/automation-controller-ui<4.6.6-1.el9a
4.6.6-1.el9a
redhat/automation-controller-venv-tower<4.6.6-1.el9a
4.6.6-1.el9a
redhat/automation-gateway-config<2.5.20250115-1.el9a
2.5.20250115-1.el9a
redhat/automation-gateway-server<2.5.20250115-1.el9a
2.5.20250115-1.el9a
redhat/python3.11-aiohttp-debuginfo<3.10.11-1.el9a
3.10.11-1.el9a
redhat/python3.11-aiohttp-debugsource<3.10.11-1.el9a
3.10.11-1.el9a
redhat/python3.11-yarl-debuginfo<1.13.1-1.el9a
1.13.1-1.el9a
redhat/python3.11-yarl-debugsource<1.13.1-1.el9a
1.13.1-1.el9a
redhat/ansible-automation-platform-installer<2.5-7.el8a
2.5-7.el8a
redhat/ansible-core<2.16.14-2.el8a
2.16.14-2.el8a
redhat/automation-controller<4.6.6-1.el8a
4.6.6-1.el8a
redhat/automation-gateway<2.5.20250115-1.el8a
2.5.20250115-1.el8a
redhat/python3.11-aiodns<3.2.0-1.el8a
3.2.0-1.el8a
redhat/python3.11-aiohappyeyeballs<2.4.4-1.el8a
2.4.4-1.el8a
redhat/python3.11-aiohttp<3.10.11-1.el8a
3.10.11-1.el8a
redhat/python3.11-django-ansible-base<2.5.20250115-1.el8a
2.5.20250115-1.el8a
redhat/python3.11-galaxy-importer<0.4.27-1.el8a
0.4.27-1.el8a
redhat/python3.11-pulpcore<3.49.29-1.el8a
3.49.29-1.el8a
redhat/python3.11-yarl<1.13.1-1.el8a
1.13.1-1.el8a
redhat/ansible-test<2.16.14-2.el8a
2.16.14-2.el8a
redhat/automation-controller-cli<4.6.6-1.el8a
4.6.6-1.el8a
redhat/automation-controller-server<4.6.6-1.el8a
4.6.6-1.el8a
redhat/automation-controller-ui<4.6.6-1.el8a
4.6.6-1.el8a
redhat/automation-controller-venv-tower<4.6.6-1.el8a
4.6.6-1.el8a
redhat/automation-gateway-config<2.5.20250115-1.el8a
2.5.20250115-1.el8a
redhat/automation-gateway-server<2.5.20250115-1.el8a
2.5.20250115-1.el8a
redhat/python3.11-aiohttp-debuginfo<3.10.11-1.el8a
3.10.11-1.el8a
redhat/python3.11-aiohttp-debugsource<3.10.11-1.el8a
3.10.11-1.el8a
redhat/python3.11-yarl-debuginfo<1.13.1-1.el8a
1.13.1-1.el8a
redhat/python3.11-yarl-debugsource<1.13.1-1.el8a
1.13.1-1.el8a

Remediation

Event History

Jan 15, 2025
Advisory Published
via Red Hat·04:44 PM
Feb 3, 2025
Advisory Published
via Red Hat·11:04 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2025:0340?

The severity of RHSA-2025:0340 is categorized as Important.

2

How do I fix RHSA-2025:0340?

To fix RHSA-2025:0340, update the affected packages to the specified versions, such as 2.5-7.el9a for ansible-automation-platform-installer.

3

What products are affected by RHSA-2025:0340?

Affected products for RHSA-2025:0340 include Red Hat Ansible Automation Platform and Red Hat Ansible Developer.

4

When was RHSA-2025:0340 released?

RHSA-2025:0340 was released to address security vulnerabilities in the affected packages.

5

What is the main focus of RHSA-2025:0340?

The main focus of RHSA-2025:0340 is to provide security and bug fix updates for Red Hat Ansible Automation Platform.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203