Skip to main content
EPSS 0.3%top 81%

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update

0
Medium
Published: 12/03/2024 (12/03/2024, 16:20:16 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: dompurify: XSS vulnerability via prototype pollution (CVE-2024-45801) * automation-controller: path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296) * ansible-core: Exposure of Sensitive Information in Ansible Vault Files Due to Improper Logging (CVE-2024-8775) * ansible-core: ansible-core user may read/write unauthorized content (CVE-2024-9902) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes for automation controller: * Fix job schedules running at incorrect times when rrule interval was set to HOURLY or MINUTELY (AAP-36573) * Fixed an issue where sensitive data was displayed in the job output (AAP-35582) * With this update, you can now save a constructed inventory when verbosity is greater than 2 (AAP-35570) * Fix bug where unrelated jobs could be marked as a dependency of other jobs (AAP-35310) * Add support for receiving webhooks from Bitbucket Data Center, and add support for posting build statuses back (AAP-35013) * Notification List no longer errors when notifications have a missing or null organization field (AAP-34051) * Fixed an issue where Thycotic secret server credentials form fields were mis-matched (AAP-31236) * automation-controller has been updated to 4.5.13 Updates and fixes for receptor: * Fixed an issue that caused a Receptor runtime panic error (AAP-36477) * receptor has been updated to 1.5.1 Updates and fixes for installer and setup: * Receptor data directory can now be configured using 'receptor_datadir' variable (AAP-36699) * Fixed issue where metrics-utility command failed to run after updating Automation controller (AAP-36567) * Fix issue where the dispatcher service went into FATAL status and failed to process new jobs after a database outage of a few minutes (AAP-36456) * Fixed an issue that caused incorrect IDs for RBAC in the database following a backup restore (AAP-35311) * With this update, installer tasks that include CA or key information are obfuscated (AAP-27480) * installer and setup have been updated to 2.4-8 Note: The 2.4-8 installer can restore a backup created with 2.4-8 or later only. Ensure that you make a backup before and after the upgrade to 2.4-8 or later.

Affected software

Affected versions
>=2.4.0 <2.4-8Red HatRed Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.4 for RHEL 8

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 20:15:58 UTC

Technical Analysis

The Red Hat Ansible Automation Platform 2.4 update addresses four security vulnerabilities: CVE-2024-45801 (XSS via prototype pollution in dompurify), CVE-2024-45296 (ReDoS due to backtracking regex in path-to-regexp), CVE-2024-8775 (exposure of sensitive information in Ansible Vault files due to improper logging), and CVE-2024-9902 (ansible-core user may read/write unauthorized content). The advisory includes fixes for these vulnerabilities along with other bug fixes in automation-controller, receptor, and installer components. The update is available in version 2.4-8 and later. The vendor rates the security impact as moderate and recommends upgrading to the fixed versions.

Potential Impact

The vulnerabilities could allow attackers to execute cross-site scripting attacks, cause denial of service through regular expression backtracking, expose sensitive information stored in Ansible Vault files, and enable unauthorized read/write operations by the ansible-core user. These issues could compromise the confidentiality and integrity of automation tasks and data managed by the platform. The overall security impact is rated moderate by Red Hat.

Mitigation Recommendations

Red Hat has released an official product update (version 2.4-8) that addresses these vulnerabilities and includes additional bug fixes. Users of Red Hat Ansible Automation Platform 2.4 should upgrade to version 2.4-8 or later. Note that the 2.4-8 installer can only restore backups created with 2.4-8 or later, so backups should be made before and after the upgrade. No other specific mitigations are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:10762
Cve Count
4
Additional Cves
["CVE-2024-9902","CVE-2024-45296","CVE-2024-45801"]

Threat ID: 6a1f4e97e29bf47b50086292

Added to database: 06/02/2026, 21:43:51 UTC

Last enriched: 08/11/2026, 20:15:58 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 148

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses