RHSA-2024:10762MediumCVSS 7.0
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
🔗 CVE IDs covered (4)
📋 Description
CVE-2024-8775 — ansible-core: Exposure of Sensitive Information in Ansible Vault Files Due to Improper Logging CVE-2024-9902 — ansible-core: Ansible-core user may read/write unauthorized content CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS CVE-2024-45801 — dompurify: XSS vulnerability via prototype pollution
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:10762
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310908
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312119
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312631
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2318271
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10762.json