Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Red Hat Ansible Automation Platform 2. 4 for RHEL 8 and 9 contains multiple security vulnerabilities including a denial of service caused by malicious JWE tokens (CVE-2024-28102), improper handling of keys with non-attribute characters in jinja2 (CVE-2024-34064), and certificate verification bypass in subsequent requests (CVE-2024-35195). Red Hat has released updates addressing these issues in automation-controller version 4. 5. 8 and related components. The update is rated as having moderate security impact. No known exploits in the wild have been reported. The vulnerabilities affect the automation-controller component of the platform, which is used to manage IT automation at scale.
AI Analysis
Technical Summary
This advisory covers three security vulnerabilities in Red Hat Ansible Automation Platform 2.4's automation-controller: CVE-2024-28102 involves a denial of service via malicious JWE tokens in the jwcrypto library; CVE-2024-34064 concerns jinja2 accepting keys with non-attribute characters potentially leading to unexpected behavior; CVE-2024-35195 allows subsequent HTTP requests to the same host to ignore certificate verification due to a flaw in the requests library. Red Hat has issued an update to automation-controller version 4.5.8 that addresses these issues along with other bug fixes. The vulnerabilities are rated as moderate in severity by Red Hat Product Security. The advisory does not provide CVSS scores but references CVE pages for detailed scoring. No known active exploitation has been reported. The update also includes fixes for configuration handling and role deletion behavior.
Potential Impact
The vulnerabilities could allow denial of service via malicious JWE tokens, potential security bypass or unexpected behavior due to improper key handling in jinja2 templates, and weakened TLS certificate verification in HTTP requests. These issues could impact the reliability and security of automation workflows managed by the platform. The overall security impact is rated moderate by Red Hat. There are no reports of known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released an official fix in automation-controller version 4.5.8 and related component updates for Ansible Automation Platform 2.4. Users should apply these updates promptly to remediate the vulnerabilities. The vendor advisory confirms the availability of these fixes. No additional mitigation steps beyond applying the official update are indicated.
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Description
Red Hat Ansible Automation Platform 2. 4 for RHEL 8 and 9 contains multiple security vulnerabilities including a denial of service caused by malicious JWE tokens (CVE-2024-28102), improper handling of keys with non-attribute characters in jinja2 (CVE-2024-34064), and certificate verification bypass in subsequent requests (CVE-2024-35195). Red Hat has released updates addressing these issues in automation-controller version 4. 5. 8 and related components. The update is rated as having moderate security impact. No known exploits in the wild have been reported. The vulnerabilities affect the automation-controller component of the platform, which is used to manage IT automation at scale.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers three security vulnerabilities in Red Hat Ansible Automation Platform 2.4's automation-controller: CVE-2024-28102 involves a denial of service via malicious JWE tokens in the jwcrypto library; CVE-2024-34064 concerns jinja2 accepting keys with non-attribute characters potentially leading to unexpected behavior; CVE-2024-35195 allows subsequent HTTP requests to the same host to ignore certificate verification due to a flaw in the requests library. Red Hat has issued an update to automation-controller version 4.5.8 that addresses these issues along with other bug fixes. The vulnerabilities are rated as moderate in severity by Red Hat Product Security. The advisory does not provide CVSS scores but references CVE pages for detailed scoring. No known active exploitation has been reported. The update also includes fixes for configuration handling and role deletion behavior.
Potential Impact
The vulnerabilities could allow denial of service via malicious JWE tokens, potential security bypass or unexpected behavior due to improper key handling in jinja2 templates, and weakened TLS certificate verification in HTTP requests. These issues could impact the reliability and security of automation workflows managed by the platform. The overall security impact is rated moderate by Red Hat. There are no reports of known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released an official fix in automation-controller version 4.5.8 and related component updates for Ansible Automation Platform 2.4. Users should apply these updates promptly to remediate the vulnerabilities. The vendor advisory confirms the availability of these fixes. No additional mitigation steps beyond applying the official update are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:4522
- Cve Count
- 3
- Additional Cves
- ["CVE-2024-34064","CVE-2024-35195"]
- Cvss Version
- null
Threat ID: 6a1f4ea1e29bf47b50088226
Added to database: 6/2/2026, 9:44:01 PM
Last enriched: 6/2/2026, 10:27:46 PM
Last updated: 6/3/2026, 5:06:32 AM
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.