Skip to main content

Threats Tagged 'cve-2024-56374'

View all threats tagged with 'cve-2024-56374'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-56374

Threats Tagged 'cve-2024-56374'

Click on any threat for detailed analysis and mitigation recommendations

Multiple security vulnerabilities affect the k8s-sidecar package. These issues are resolved in later releases. See references for individual vulnerability details.

Join the discussion
0

Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): * python-django: Potential denial-of-service vulnerability in IPv6 validation (CVE-2024-56374) * python-jinja2: Sandbox breakout through indirect reference to format method (CVE-2024-56326) * rubygem-rack: Local File Inclusion in Rack::Static (CVE-2025-27610) * rubygem-graphql: Remote code execution when loading a crafted GraphQL schema (CVE-2025-27407)

Join the discussion

A moderate severity denial-of-service vulnerability (CVE-2024-56374) exists in the ansible-lightspeed-container component of Red Hat Ansible Automation Platform 2.5. This vulnerability relates to IPv6 validation and could potentially allow disruption of service. Red Hat has released updates including Automation Controller 4.6.7, Automation EDA Controller 1.1.4, and Ansible Lightspeed 2.5.20250121 to address this issue. The advisory also includes other configuration improvements unrelated to the vulnerability. The affected products include Red Hat Ansible Automation Platform 2.5 for RHEL 8 and RHEL 9 across multiple architectures. No known exploits in the wild have been reported. Patch status is confirmed with updated component versions provided by Red Hat.

Join the discussion

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: Jinja has a sandbox breakout through indirect reference to format method (CVE-2024-56326) * automation-controller: Jinja has a sandbox breakout through malicious filenames (CVE-2024-56201) * automation-controller: Django: potential denial-of-service vulnerability in IPv6 validation (CVE-2024-56374) * python3.11-django: potential denial-of-service vulnerability in IPv6 validation (CVE-2024-56374) * python3.11-django: Potential denial-of-service in django.utils.html.strip_tags() (CVE-2024-53907) * python3.11-jinja2: Jinja has a sandbox breakout through indirect reference to format method (CVE-2024-56326) * python3.11-jinja2: Jinja has a sandbox breakout through malicious filenames (CVE-2024-56201) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Automation controller * Fixed an issue where the order of source inventories was not respected by the ansible.controller collection (AAP-38524) * Fixed an issue where an actively running job on an execution node may have had its folder deleted by a system task (AAP-38137) * automation-controller has been updated to 4.6.7 Event-Driven Ansible: * Fixed an issue where users were unable to filter Rule Audits by rulebook activation name (AAP-39253) * Users are now able to create a new Event-Driven Ansible credential by copying an existing one (AAP-39249) * Added support for file and env injectors for Credentials (AAP-39091) * Fixed an issue where the input field of the injector configuration could not be empty (AAP-39086) * Fixed an issue where the application version in the openapi spec was incorrectly set (AAP-38392) * Fixed an issue where activations were not properly updated in some scenarios with a high load of the system (AAP-38374) * automation-eda-controller has been updated to 1.1.4 Container-based Ansible Automation Platform * Allow user to not provide the Postgresql admin account with external database (AAP-39077) * Using PostgreSQL TLS certificate authentication with an external database is now available (AAP-38400) * containerized installer setup has been updated to 2.5-9 RPM-based Ansible Automation Platform * Fixed an issue where gateway could not be setup with custom SSL certificates (AAP-38985) * Fixed an issue where the gateway services are not restarted when a dependency changes (AAP-38918) * Fixed an issue where setting automationedacontroller_max_running_activations could cause the installer to fail (AAP-38708) * ansible-automation-platform-installer and installer setup have been updated to 2.5-8 Additional changes: * python3.11-django has been updated to 4.2.18 * python3.11-jinja2 has been updated to 3.1.5 * python3.11-pulpcore has been updated to 3.49.30

Join the discussion

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * ansible-lightspeed-container: Jinja has a sandbox breakout through malicious filenames (CVE-2024-56201) * ansible-lightspeed-container: Jinja has a sandbox breakout through indirect reference to format method (CVE-2024-56326) * ansible-lightspeed-container: aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions (CVE-2024-52304) * ansible-lightspeed-container: Denial of Service through Data corruption in gRPC-C++ (CVE-2024-11407) Update(s) and fix(es): * The ansible.controller collection has been updated to 4.6.6 (AAP-38443) * Database replicas can now be configured for the operator-managed AAP centralized PostgreSQL database (AAP-38145) * Apply EDA API resource requirements for cpu and memory to the nginx container that serves up the browsable API for EDA. Allow overriding memory requests and limits to satisfy ResourceQuotas in quota constrained environments (AAP-38140)

Join the discussion

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: Potential SQL injection in HasKey(lhs, rhs) on Oracle (CVE-2024-53908) * automation-controller: Potential denial-of-service in django.utils.html.strip_tags() (CVE-2024-53907) * automation-controller: Denial of Service through Data corruption in gRPC-C++ (CVE-2024-11407) * automation-gateway: nanoid mishandles non-integer values (CVE-2024-55565) * python3.11-aiohttp: aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions (CVE-2024-52304) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Platform * Fixed 'not found' error that occurred occasionally when navigating form wizards (AAP-37495) * Fixed an issue where ID_KEY attribute was improperly used to determine the username field in social auth pipelines (AAP-38300) * Fixed an issue where the X-DAB-JW-TOKEN header message would flood logs (AAP-38169) * Fixed an issue where authenticator could create a userid and return a non-viable authenticator_uid (AAP-38021) * Enhanced the status API, /api/gateway/v1/status/, from the services property within the JSON to an array (AAP-37903) * Fixes an issue where a private key was displayed in plain text when downloading the OpenAPI schema file. NOTE: This was not the private key used by gateway, just a random default key (AAP-37843) Automation controller * Added 'job_lifecycle' as a choice in loggers to send externally and added 'organization_id' field to logs related to a job (AAP-37537) * Fixed date comparison mismatch for traceback from 'host_metric_summary_monthly' task (AAP-37487) * Fixed scheduled jobs with count set to a non-zero value to no longer run unexpectedly (AAP-37290) * Fixed the POST operation to '/api/controller/login/' via gateway to no longer result in a fatal error (AAP-37235) * Fixed the behavior of the project's 'requirements.yml' to no longer revert to a prior state in a cluster (AAP-37228) * Fixed occasional error while creating event partition table before starting a job, when lots of jobs are launched quickly (AAP-37227) * Fixed the named URL to no longer return a 404 error code while launching a job template (AAP-37025) * Updated receptor to clean up temporary receptor files after a job completes on nodes (AAP-36904) * Fixed the POST operation to '/api/controller/login/' via gateway to no longer result in a fatal error (AAP-33911) * automation-controller has been updated to 4.6.6 Container-based Ansible Automation Platform * Fixed an issue where the provided inventory file sample for growth inventories could cause the installation to stall on low resource systems (AAP-38372) * Fixed an issue where the throttle capacity of controller in growth topology installation would allow for performance degradation (AAP-38207) * Fixed an issue where the receptor TLS certificate content was not validated during the preflight role execution ensuring that the x509 Subject Alt Name (SAN) field contains the required ISO Object Identifier (OID) (AAP-37880) * TLS certificate and key files are now validated during the preflight role execution (AAP-37845) * Fixed an issue where the Postgresql SSL mode variables were not validated during the preflight role execution (AAP-37352) * containerized installer setup has been updated to 2.5-8 RPM-based Ansible Automation Platform * Fixed an issue where adding a new automation hub host to upgraded environment has caused the installation to fail (AAP-38204) * Fixed an issue where the link to the documents in the installer README.md was broken (AAP-37627) * Updated nginx configuration to properly return API status for Event-Driven Ansible event stream service (AAP-32816) * ansible-automation-platform-installer and installer setup have been updated to 2.5-7 Additional changes: * Installing ansible-core no longer installs python3-jmespath on RHEL 8 (AAP-18251) * ansible-core has been updated to 2.16.14-2 * automation-gateway has been updated to 2.5.20250115 * python3.11-aiohttp has been updated to 3.10.11 along with its dependencies * python3.11-django-ansible-base has been updated to 2.5.20250115 * python3.11-galaxy-importer has been updated to 0.4.27 * python3.11-pulpcore has been updated to 3.49.29

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cve-2024-56374
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses