Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: dompurify: XSS vulnerability via prototype pollution (CVE-2024-45801) * automation-controller: path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296) * ansible-core: Exposure of Sensitive Information in Ansible Vault Files Due to Improper Logging (CVE-2024-8775) * ansible-core: ansible-core user may read/write unauthorized content (CVE-2024-9902) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes for automation controller: * Fix job schedules running at incorrect times when rrule interval was set to HOURLY or MINUTELY (AAP-36573) * Fixed an issue where sensitive data was displayed in the job output (AAP-35582) * With this update, you can now save a constructed inventory when verbosity is greater than 2 (AAP-35570) * Fix bug where unrelated jobs could be marked as a dependency of other jobs (AAP-35310) * Add support for receiving webhooks from Bitbucket Data Center, and add support for posting build statuses back (AAP-35013) * Notification List no longer errors when notifications have a missing or null organization field (AAP-34051) * Fixed an issue where Thycotic secret server credentials form fields were mis-matched (AAP-31236) * automation-controller has been updated to 4.5.13 Updates and fixes for receptor: * Fixed an issue that caused a Receptor runtime panic error (AAP-36477) * receptor has been updated to 1.5.1 Updates and fixes for installer and setup: * Receptor data directory can now be configured using 'receptor_datadir' variable (AAP-36699) * Fixed issue where metrics-utility command failed to run after updating Automation controller (AAP-36567) * Fix issue where the dispatcher service went into FATAL status and failed to process new jobs after a database outage of a few minutes (AAP-36456) * Fixed an issue that caused incorrect IDs for RBAC in the database following a backup restore (AAP-35311) * With this update, installer tasks that include CA or key information are obfuscated (AAP-27480) * installer and setup have been updated to 2.4-8 Note: The 2.4-8 installer can restore a backup created with 2.4-8 or later only. Ensure that you make a backup before and after the upgrade to 2.4-8 or later.
AI Analysis
Technical Summary
The Red Hat Ansible Automation Platform 2.4 update addresses four security vulnerabilities: CVE-2024-45801 (XSS via prototype pollution in dompurify), CVE-2024-45296 (ReDoS due to backtracking regex in path-to-regexp), CVE-2024-8775 (exposure of sensitive information in Ansible Vault files due to improper logging), and CVE-2024-9902 (ansible-core user may read/write unauthorized content). The advisory includes fixes for these vulnerabilities along with other bug fixes in automation-controller, receptor, and installer components. The update is available in version 2.4-8 and later. The vendor rates the security impact as moderate and recommends upgrading to the fixed versions.
Potential Impact
The vulnerabilities could allow attackers to execute cross-site scripting attacks, cause denial of service through regular expression backtracking, expose sensitive information stored in Ansible Vault files, and enable unauthorized read/write operations by the ansible-core user. These issues could compromise the confidentiality and integrity of automation tasks and data managed by the platform. The overall security impact is rated moderate by Red Hat.
Mitigation Recommendations
Red Hat has released an official product update (version 2.4-8) that addresses these vulnerabilities and includes additional bug fixes. Users of Red Hat Ansible Automation Platform 2.4 should upgrade to version 2.4-8 or later. Note that the 2.4-8 installer can only restore backups created with 2.4-8 or later, so backups should be made before and after the upgrade. No other specific mitigations are indicated by the vendor advisory.
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Description
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: dompurify: XSS vulnerability via prototype pollution (CVE-2024-45801) * automation-controller: path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296) * ansible-core: Exposure of Sensitive Information in Ansible Vault Files Due to Improper Logging (CVE-2024-8775) * ansible-core: ansible-core user may read/write unauthorized content (CVE-2024-9902) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes for automation controller: * Fix job schedules running at incorrect times when rrule interval was set to HOURLY or MINUTELY (AAP-36573) * Fixed an issue where sensitive data was displayed in the job output (AAP-35582) * With this update, you can now save a constructed inventory when verbosity is greater than 2 (AAP-35570) * Fix bug where unrelated jobs could be marked as a dependency of other jobs (AAP-35310) * Add support for receiving webhooks from Bitbucket Data Center, and add support for posting build statuses back (AAP-35013) * Notification List no longer errors when notifications have a missing or null organization field (AAP-34051) * Fixed an issue where Thycotic secret server credentials form fields were mis-matched (AAP-31236) * automation-controller has been updated to 4.5.13 Updates and fixes for receptor: * Fixed an issue that caused a Receptor runtime panic error (AAP-36477) * receptor has been updated to 1.5.1 Updates and fixes for installer and setup: * Receptor data directory can now be configured using 'receptor_datadir' variable (AAP-36699) * Fixed issue where metrics-utility command failed to run after updating Automation controller (AAP-36567) * Fix issue where the dispatcher service went into FATAL status and failed to process new jobs after a database outage of a few minutes (AAP-36456) * Fixed an issue that caused incorrect IDs for RBAC in the database following a backup restore (AAP-35311) * With this update, installer tasks that include CA or key information are obfuscated (AAP-27480) * installer and setup have been updated to 2.4-8 Note: The 2.4-8 installer can restore a backup created with 2.4-8 or later only. Ensure that you make a backup before and after the upgrade to 2.4-8 or later.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat Ansible Automation Platform 2.4 update addresses four security vulnerabilities: CVE-2024-45801 (XSS via prototype pollution in dompurify), CVE-2024-45296 (ReDoS due to backtracking regex in path-to-regexp), CVE-2024-8775 (exposure of sensitive information in Ansible Vault files due to improper logging), and CVE-2024-9902 (ansible-core user may read/write unauthorized content). The advisory includes fixes for these vulnerabilities along with other bug fixes in automation-controller, receptor, and installer components. The update is available in version 2.4-8 and later. The vendor rates the security impact as moderate and recommends upgrading to the fixed versions.
Potential Impact
The vulnerabilities could allow attackers to execute cross-site scripting attacks, cause denial of service through regular expression backtracking, expose sensitive information stored in Ansible Vault files, and enable unauthorized read/write operations by the ansible-core user. These issues could compromise the confidentiality and integrity of automation tasks and data managed by the platform. The overall security impact is rated moderate by Red Hat.
Mitigation Recommendations
Red Hat has released an official product update (version 2.4-8) that addresses these vulnerabilities and includes additional bug fixes. Users of Red Hat Ansible Automation Platform 2.4 should upgrade to version 2.4-8 or later. Note that the 2.4-8 installer can only restore backups created with 2.4-8 or later, so backups should be made before and after the upgrade. No other specific mitigations are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:10762
- Cve Count
- 4
- Additional Cves
- ["CVE-2024-9902","CVE-2024-45296","CVE-2024-45801"]
Threat ID: 6a1f4e97e29bf47b50086292
Added to database: 06/02/2026, 21:43:51 UTC
Last enriched: 08/11/2026, 20:15:58 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 148
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.