Skip to main content
EPSS 0.3%top 81%

Red Hat Security Advisory: Red Hat Ansible Automation Platform Execution Environments Container Release Update

0
Medium
Published: 11/06/2024 (11/06/2024, 17:11:54 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ansible Automation Platform Execution Environments have been updated to address two security vulnerabilities in ansible-core: CVE-2024-8775, which involves exposure of sensitive information in Ansible Vault files due to improper logging, and CVE-2024-9902, where an ansible-core user may read or write unauthorized content. These issues are rated as moderate severity by Red Hat and fixed in updated ansible-core versions 2.16.13, 2.17.6, and the newly added 2.18.0. The advisory covers multiple architectures including s390x, x86_64, ppc64le, and aarch64. No CVSS score is provided for these vulnerabilities.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 23:17:15 UTC

Technical Analysis

This Red Hat security advisory addresses two vulnerabilities in the ansible-core component of the Red Hat Ansible Automation Platform Execution Environments container. CVE-2024-8775 is an exposure of sensitive information in Ansible Vault files caused by improper logging practices. CVE-2024-9902 allows an ansible-core user to read or write content without proper authorization. Red Hat has released updated ansible-core versions 2.16.13 and 2.17.6 for the ee-minimal 2.16 and 2.17 streams respectively, and introduced version 2.18.0 for the 2.18 stream, which include fixes for these issues. The advisory applies to multiple hardware architectures and is classified as moderate severity. No known exploits in the wild have been reported at this time.

Potential Impact

The vulnerabilities could lead to unauthorized exposure of sensitive information stored in Ansible Vault files and unauthorized read/write access by ansible-core users. This may compromise confidentiality and integrity of automation content managed by the platform. However, the severity is rated moderate, and no active exploitation has been reported.

Mitigation Recommendations

Red Hat has provided official fixes by updating ansible-core to versions 2.16.13, 2.17.6, and adding 2.18.0 in the Ansible Automation Platform Execution Environments. Users should update to these fixed versions as soon as possible to mitigate the vulnerabilities. No additional mitigation steps are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:8969
Cve Count
2
Additional Cves
["CVE-2024-9902"]

Threat ID: 6a1f4e9ce29bf47b5008693d

Added to database: 06/02/2026, 21:43:56 UTC

Last enriched: 08/06/2026, 23:17:15 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 102

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses