Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
🔗 CVE IDs covered (12)
📋 Description
CVE-2023-39326 — golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests
CVE-2023-41040 — GitPython: Blind local file inclusion
CVE-2023-45857 — axios: exposure of confidential data stored in cookies
CVE-2023-46137 — python-twisted: disordered HTTP pipeline response in twisted.web
CVE-2023-47627 — python-aiohttp: numerous issues in HTTP parser with header parsing
CVE-2023-49083 — python-cryptography: NULL-dereference when loading PKCS7 certificates
CVE-2024-1394 — golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads
CVE-2024-22195 — jinja2: HTML attribute injection when passing user input as keys to xmlattr filter
CVE-2024-23334 — aiohttp: follow_symlinks directory traversal vulnerability
CVE-2024-23829 — python-aiohttp: http request smuggling
CVE-2024-24680 — Django: denial-of-service in intcomma template filter
CVE-2024-27351 — python-django: Potential regular expression denial-of-service in django.utils.text.Truncator.words()
🎯 Affected products84
- Red Hat Ansible Automation Platform 2.4 for RHEL 8
- Red Hat Ansible Automation Platform 2.4 for RHEL 9
- ansible-core-1:2.15.10-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- ansible-core-1:2.15.10-1.el8ap.src as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- ansible-core-1:2.15.10-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- ansible-core-1:2.15.10-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- ansible-runner-0:2.3.6-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- ansible-runner-0:2.3.6-1.el8ap.src as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- ansible-runner-0:2.3.6-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- ansible-runner-0:2.3.6-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- ansible-test-1:2.15.10-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- ansible-test-1:2.15.10-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-0:4.5.5-2.el8ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-0:4.5.5-2.el8ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-0:4.5.5-2.el8ap.s390x as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-0:4.5.5-2.el8ap.src as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-0:4.5.5-2.el8ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-0:4.5.5-2.el9ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-0:4.5.5-2.el9ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-0:4.5.5-2.el9ap.s390x as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-0:4.5.5-2.el9ap.src as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-0:4.5.5-2.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-cli-0:4.5.5-2.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-cli-0:4.5.5-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-server-0:4.5.5-2.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-server-0:4.5.5-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-ui-0:4.5.5-2.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-ui-0:4.5.5-2.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 9
- automation-controller-venv-tower-0:4.5.5-2.el8ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- automation-controller-venv-tower-0:4.5.5-2.el8ap.ppc64le as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
- +54 more not shown
✅ Remediation
Red Hat Ansible Automation Platform Workaround: No mitigation is available for this flaw. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: If using follow_symlinks=True outside of a restricted local development environment, disable the option immediately. This option is NOT needed to follow symlinks that point to a location within the static root directory; it is only intended to allow a symlink to break out of the static directory. Even with this CVE fixed, there is still a substantial risk of misconfiguration when using this option on a server that accepts requests from remote users. Additionally, aiohttp has always recommended using a reverse proxy server (such as nginx) to handle static resources and not to use these static resources in aiohttp for production environments. Doing so also protects against this vulnerability, and is why we expect the number of affected users to be very low.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2024:1640
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2246264
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247040
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2248979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2249825
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255331
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2261856
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2261887
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2261909
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262921
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266045
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1640.json