Red Hat Security Advisory: Red Hat Ansible Automation Platform Execution Environments Container Release Update
Red Hat Ansible Automation Platform Execution Environments have been updated to address two security vulnerabilities in ansible-core: CVE-2024-8775, which involves exposure of sensitive information in Ansible Vault files due to improper logging, and CVE-2024-9902, where an ansible-core user may read or write unauthorized content. These issues are rated as moderate severity by Red Hat and fixed in updated ansible-core versions 2.16.13, 2.17.6, and the newly added 2.18.0. The advisory covers multiple architectures including s390x, x86_64, ppc64le, and aarch64. No CVSS score is provided for these vulnerabilities.
AI Analysis
Technical Summary
This Red Hat security advisory addresses two vulnerabilities in the ansible-core component of the Red Hat Ansible Automation Platform Execution Environments container. CVE-2024-8775 is an exposure of sensitive information in Ansible Vault files caused by improper logging practices. CVE-2024-9902 allows an ansible-core user to read or write content without proper authorization. Red Hat has released updated ansible-core versions 2.16.13 and 2.17.6 for the ee-minimal 2.16 and 2.17 streams respectively, and introduced version 2.18.0 for the 2.18 stream, which include fixes for these issues. The advisory applies to multiple hardware architectures and is classified as moderate severity. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities could lead to unauthorized exposure of sensitive information stored in Ansible Vault files and unauthorized read/write access by ansible-core users. This may compromise confidentiality and integrity of automation content managed by the platform. However, the severity is rated moderate, and no active exploitation has been reported.
Mitigation Recommendations
Red Hat has provided official fixes by updating ansible-core to versions 2.16.13, 2.17.6, and adding 2.18.0 in the Ansible Automation Platform Execution Environments. Users should update to these fixed versions as soon as possible to mitigate the vulnerabilities. No additional mitigation steps are indicated by the vendor advisory.
Red Hat Security Advisory: Red Hat Ansible Automation Platform Execution Environments Container Release Update
Description
Red Hat Ansible Automation Platform Execution Environments have been updated to address two security vulnerabilities in ansible-core: CVE-2024-8775, which involves exposure of sensitive information in Ansible Vault files due to improper logging, and CVE-2024-9902, where an ansible-core user may read or write unauthorized content. These issues are rated as moderate severity by Red Hat and fixed in updated ansible-core versions 2.16.13, 2.17.6, and the newly added 2.18.0. The advisory covers multiple architectures including s390x, x86_64, ppc64le, and aarch64. No CVSS score is provided for these vulnerabilities.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory addresses two vulnerabilities in the ansible-core component of the Red Hat Ansible Automation Platform Execution Environments container. CVE-2024-8775 is an exposure of sensitive information in Ansible Vault files caused by improper logging practices. CVE-2024-9902 allows an ansible-core user to read or write content without proper authorization. Red Hat has released updated ansible-core versions 2.16.13 and 2.17.6 for the ee-minimal 2.16 and 2.17 streams respectively, and introduced version 2.18.0 for the 2.18 stream, which include fixes for these issues. The advisory applies to multiple hardware architectures and is classified as moderate severity. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities could lead to unauthorized exposure of sensitive information stored in Ansible Vault files and unauthorized read/write access by ansible-core users. This may compromise confidentiality and integrity of automation content managed by the platform. However, the severity is rated moderate, and no active exploitation has been reported.
Mitigation Recommendations
Red Hat has provided official fixes by updating ansible-core to versions 2.16.13, 2.17.6, and adding 2.18.0 in the Ansible Automation Platform Execution Environments. Users should update to these fixed versions as soon as possible to mitigate the vulnerabilities. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:8969
- Cve Count
- 2
- Additional Cves
- ["CVE-2024-9902"]
Threat ID: 6a1f4e9ce29bf47b5008693d
Added to database: 06/02/2026, 21:43:56 UTC
Last enriched: 08/06/2026, 23:17:15 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 102
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.