Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Ansible DevSpaces Container Release Update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-59681 — django: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB1 CVE-2025-59682 — django: Potential partial directory-traversal via archive.extract() CVE-2025-64459 — django: Django SQL injection
🎯 Affected products5
- Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-tech-preview/ansible-devspaces-rhel9@sha256:020f49ce6da38f7ea894297143c18f6b1fa6a6986a9ef78d33f6e359a24e35b9_ppc64le as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-tech-preview/ansible-devspaces-rhel9@sha256:5c2b7437a4e6c96e98e0cdbd926295ec34e221cbd53d688362719bf37187faff_amd64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-tech-preview/ansible-devspaces-rhel9@sha256:8570386a64686788159d361f55b1b5bc9eb350a82048b386b476ae2ea83e374e_arm64 as a component of Red Hat Ansible Automation Platform 2.6
- registry.redhat.io/ansible-automation-platform-tech-preview/ansible-devspaces-rhel9@sha256:b7813e84cddc3ea6ad097d51b3316f2021fc31af6826cfad31a8de826d38e549_s390x as a component of Red Hat Ansible Automation Platform 2.6
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrading Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:23196
- externalhttps://access.redhat.com/security/cve/CVE-2025-59681
- externalhttps://access.redhat.com/security/cve/CVE-2025-59682
- externalhttps://access.redhat.com/security/cve/CVE-2025-64459
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/html/release_notes/patch_releases
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23196.json