RHSA-2023:4971MediumCVSS 9.8
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-23931 — python-cryptography: memory corruption via immutable objects CVE-2023-40267 — GitPython: Insecure non-multi options in clone and clone_from is not blocked
🎯 Affected products36
- Red Hat Ansible Automation Platform 2.4 for RHEL 8
- Red Hat Ansible Automation Platform 2.4 for RHEL 9
- ansible-core-0:2.15.3-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- ansible-core-0:2.15.3-1.el8ap.src as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- ansible-core-0:2.15.3-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- ansible-core-0:2.15.3-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- ansible-test-0:2.15.3-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- ansible-test-0:2.15.3-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-0:4.4.3-1.el8ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-0:4.4.3-1.el8ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-0:4.4.3-1.el8ap.s390x as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-0:4.4.3-1.el8ap.src as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-0:4.4.3-1.el8ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-0:4.4.3-1.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-0:4.4.3-1.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-0:4.4.3-1.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-0:4.4.3-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-0:4.4.3-1.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-cli-0:4.4.3-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-cli-0:4.4.3-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-server-0:4.4.3-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-server-0:4.4.3-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-ui-0:4.4.3-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-ui-0:4.4.3-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-venv-tower-0:4.4.3-1.el8ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-venv-tower-0:4.4.3-1.el8ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-venv-tower-0:4.4.3-1.el8ap.s390x as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-venv-tower-0:4.4.3-1.el8ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-venv-tower-0:4.4.3-1.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-venv-tower-0:4.4.3-1.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- +6 more not shown
✅ Remediation
Red Hat Ansible Automation Platform
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2023:4971
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2171817
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231474
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4971.json