Skip to main content

Threats Tagged 'cve-2024-53907'

View all threats tagged with 'cve-2024-53907'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-53907

Threats Tagged 'cve-2024-53907'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: Jinja has a sandbox breakout through indirect reference to format method (CVE-2024-56326) * automation-controller: Jinja has a sandbox breakout through malicious filenames (CVE-2024-56201) * automation-controller: Django: potential denial-of-service vulnerability in IPv6 validation (CVE-2024-56374) * python3.11-django: potential denial-of-service vulnerability in IPv6 validation (CVE-2024-56374) * python3.11-django: Potential denial-of-service in django.utils.html.strip_tags() (CVE-2024-53907) * python3.11-jinja2: Jinja has a sandbox breakout through indirect reference to format method (CVE-2024-56326) * python3.11-jinja2: Jinja has a sandbox breakout through malicious filenames (CVE-2024-56201) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Automation controller * Fixed an issue where the order of source inventories was not respected by the ansible.controller collection (AAP-38524) * Fixed an issue where an actively running job on an execution node may have had its folder deleted by a system task (AAP-38137) * automation-controller has been updated to 4.6.7 Event-Driven Ansible: * Fixed an issue where users were unable to filter Rule Audits by rulebook activation name (AAP-39253) * Users are now able to create a new Event-Driven Ansible credential by copying an existing one (AAP-39249) * Added support for file and env injectors for Credentials (AAP-39091) * Fixed an issue where the input field of the injector configuration could not be empty (AAP-39086) * Fixed an issue where the application version in the openapi spec was incorrectly set (AAP-38392) * Fixed an issue where activations were not properly updated in some scenarios with a high load of the system (AAP-38374) * automation-eda-controller has been updated to 1.1.4 Container-based Ansible Automation Platform * Allow user to not provide the Postgresql admin account with external database (AAP-39077) * Using PostgreSQL TLS certificate authentication with an external database is now available (AAP-38400) * containerized installer setup has been updated to 2.5-9 RPM-based Ansible Automation Platform * Fixed an issue where gateway could not be setup with custom SSL certificates (AAP-38985) * Fixed an issue where the gateway services are not restarted when a dependency changes (AAP-38918) * Fixed an issue where setting automationedacontroller_max_running_activations could cause the installer to fail (AAP-38708) * ansible-automation-platform-installer and installer setup have been updated to 2.5-8 Additional changes: * python3.11-django has been updated to 4.2.18 * python3.11-jinja2 has been updated to 3.1.5 * python3.11-pulpcore has been updated to 3.49.30

Join the discussion

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: Potential SQL injection in HasKey(lhs, rhs) on Oracle (CVE-2024-53908) * automation-controller: Potential denial-of-service in django.utils.html.strip_tags() (CVE-2024-53907) * automation-controller: Denial of Service through Data corruption in gRPC-C++ (CVE-2024-11407) * automation-gateway: nanoid mishandles non-integer values (CVE-2024-55565) * python3.11-aiohttp: aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions (CVE-2024-52304) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Platform * Fixed 'not found' error that occurred occasionally when navigating form wizards (AAP-37495) * Fixed an issue where ID_KEY attribute was improperly used to determine the username field in social auth pipelines (AAP-38300) * Fixed an issue where the X-DAB-JW-TOKEN header message would flood logs (AAP-38169) * Fixed an issue where authenticator could create a userid and return a non-viable authenticator_uid (AAP-38021) * Enhanced the status API, /api/gateway/v1/status/, from the services property within the JSON to an array (AAP-37903) * Fixes an issue where a private key was displayed in plain text when downloading the OpenAPI schema file. NOTE: This was not the private key used by gateway, just a random default key (AAP-37843) Automation controller * Added 'job_lifecycle' as a choice in loggers to send externally and added 'organization_id' field to logs related to a job (AAP-37537) * Fixed date comparison mismatch for traceback from 'host_metric_summary_monthly' task (AAP-37487) * Fixed scheduled jobs with count set to a non-zero value to no longer run unexpectedly (AAP-37290) * Fixed the POST operation to '/api/controller/login/' via gateway to no longer result in a fatal error (AAP-37235) * Fixed the behavior of the project's 'requirements.yml' to no longer revert to a prior state in a cluster (AAP-37228) * Fixed occasional error while creating event partition table before starting a job, when lots of jobs are launched quickly (AAP-37227) * Fixed the named URL to no longer return a 404 error code while launching a job template (AAP-37025) * Updated receptor to clean up temporary receptor files after a job completes on nodes (AAP-36904) * Fixed the POST operation to '/api/controller/login/' via gateway to no longer result in a fatal error (AAP-33911) * automation-controller has been updated to 4.6.6 Container-based Ansible Automation Platform * Fixed an issue where the provided inventory file sample for growth inventories could cause the installation to stall on low resource systems (AAP-38372) * Fixed an issue where the throttle capacity of controller in growth topology installation would allow for performance degradation (AAP-38207) * Fixed an issue where the receptor TLS certificate content was not validated during the preflight role execution ensuring that the x509 Subject Alt Name (SAN) field contains the required ISO Object Identifier (OID) (AAP-37880) * TLS certificate and key files are now validated during the preflight role execution (AAP-37845) * Fixed an issue where the Postgresql SSL mode variables were not validated during the preflight role execution (AAP-37352) * containerized installer setup has been updated to 2.5-8 RPM-based Ansible Automation Platform * Fixed an issue where adding a new automation hub host to upgraded environment has caused the installation to fail (AAP-38204) * Fixed an issue where the link to the documents in the installer README.md was broken (AAP-37627) * Updated nginx configuration to properly return API status for Event-Driven Ansible event stream service (AAP-32816) * ansible-automation-platform-installer and installer setup have been updated to 2.5-7 Additional changes: * Installing ansible-core no longer installs python3-jmespath on RHEL 8 (AAP-18251) * ansible-core has been updated to 2.16.14-2 * automation-gateway has been updated to 2.5.20250115 * python3.11-aiohttp has been updated to 3.10.11 along with its dependencies * python3.11-django-ansible-base has been updated to 2.5.20250115 * python3.11-galaxy-importer has been updated to 0.4.27 * python3.11-pulpcore has been updated to 3.49.29

Join the discussion
CVE-2024-53907: n/aCVE-2024-53907
0

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2024-53907
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses