Red Hat Security Advisory: Red Hat Ansible Automation Platform Execution Environments Container Release Update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-8775 — ansible-core: Exposure of Sensitive Information in Ansible Vault Files Due to Improper Logging CVE-2024-9902 — ansible-core: Ansible-core user may read/write unauthorized content
🎯 Affected products46
- Ansible Automation Platform Execution Environments
- ansible-automation-platform/ansible-builder-rhel8@sha256:2901c7889c6bac6b18716de9d5a791f1100ef6d413b4243c3bd92b7ff7c22ab9_amd64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ansible-builder-rhel8@sha256:39d7571e339d054be040ce31a36e4f092113cc19e9b3fe8682253a0fceb9b87d_amd64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ansible-builder-rhel8@sha256:7ab9a0db46fd4101508523f4883ce44db218646b4fbc0440672414e952f26c63_ppc64le as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ansible-builder-rhel8@sha256:ef45f6c736ac6f3eda6f81754fb023d6f17cac5925396130c7b12c90ff2df473_arm64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ansible-builder-rhel8@sha256:fd6a709ebfcafa6bc6510e27818dd4a1055c072a890fbc30a18f1edf1a408dd9_s390x as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ansible-builder-rhel9@sha256:a7d2eb9f8caf873816f624e5aa4bb32e559659210a23ca2ba2795d9d1f1d593f_arm64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ansible-builder-rhel9@sha256:be870a0d19d3fbc5990f071ec29f890a2e5397ddc8ede09f43b17edde945c496_amd64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ansible-builder-rhel9@sha256:c99c4eee73b2ced948760e625d5b9d275ad363c138f8d182c1f028c284edb1c2_ppc64le as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ansible-builder-rhel9@sha256:d033e4505ac2f36c3f360e72a76b8488749feb959b678e6aef712b589c552200_s390x as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-29-rhel8@sha256:173b451020601af0feeb8ae9cd179f26dd1c739c65f2eb0ed98221e450956300_amd64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:19fd510263db0b13d2693be89eb9d05f52376936adab010f4e57321dd989a45f_amd64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:255c76bbdbe20f1c48e4f432ec32027cef383dc40f6ba0baac911777db37d163_s390x as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:367ce9cd1d1b4939eafc66fed161ba44873a877c61d3177a558c35f61802c229_ppc64le as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:38b9a053a22e0d7479108b51395dd36671f745c88549e13584505a7ac62155f6_s390x as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:5e921bb706ca6704425351748ba786a86b67112a3aee2528e42dedefb0c1bc29_amd64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:70e28f489f8b4e276fd5ba757ef7c9efad4a19e73ffc2f7026e31eb90e709e18_s390x as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:787ac9e8e7bbd228cbd52fc4d20d08330df2285c172e1f9bc2537b85c36f47a4_arm64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:84ca336d97b203e226777a99f1b785d7ce75e385e0be9fef376985f545ba01e5_arm64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:93cb5f7a7776004fef4950515cf6682a88877f984202bfabfbef995440ba40ad_arm64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:9ed8205b228fe1f83da12dd47475363d314fba58a4919a3c8f24ad0bfa105899_amd64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:a0171e315be9d4112cecc893283b24bd728a21414ec23551d84fdc55b4043dab_ppc64le as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:a4bc4c2aa73968cd688a04b1b57f4a58dc5789b3ff76fb40a3db760ce97bb0a6_ppc64le as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:adf3cd868bb21a3982e6d5da39236235cf92883b24879556ff2232f81bfa6f91_ppc64le as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:b87cd26f01171a9cfd43efa025619b5dc5080a5e596668142637064380d07e70_amd64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:d6c2029c24be99607aed86cf8f8ba5cd51b2a7527a6d3f486f20c570a4e6000d_amd64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:e6c3b8e68a55e7b1cb0a0a3a737bb1294f60339d24573db80de84e6a37ef9cb6_arm64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:e74f12f655a6644877ce56fb6b1dacbb0b689c0c13306699a66f53b075453581_amd64 as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:e8bd472d19f44dfcc0524a4725d7378a4ab9ef8b07cf6478927b3bfe8d2b43a2_s390x as a component of Ansible Automation Platform Execution Environments
- ansible-automation-platform/ee-minimal-rhel8@sha256:f3ca48307c3a0ce65364d65f088d43a778856778c09eed01b0190067271d5a35_amd64 as a component of Ansible Automation Platform Execution Environments
- +16 more not shown
✅ Remediation
Red Hat Ansible Automation Platform Execution Environments Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: In the play that uses the user module with the key generation option, have a prior task ensuring the public key does not exist for example: - name: avoid user exploit (change name depending on other options used in user task) file: path=/home/{{username}}/.ssh/id_rsa.pub state=absent
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:8969
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312119
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2318271
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8969.json