Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:10770 - Security Advisory
Issued:
2024-12-03
Updated:
2024-12-03

RHSA-2024:10770 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat Ansible Automation Platform Execution Environments Container Release Update

Type/Severity

Security Advisory: Moderate

Topic

An update is now available for Red Hat Ansible Automation Platform Execution Environments

Description

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language.

Security Fix(es):

  • ansible-core: Unsafe Tagging Bypass via hostvars Object in Ansible-Core (CVE-2024-11079)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updates and fixes:

  • ansible-core has been updated to 2.15.13 (ee-minimal 2.15 stream)
  • ansible-core has been updated to 2.16.14 (ee-minimal 2.16 stream)
  • ansible-core has been updated to 2.17.7 (ee-minimal 2.17 stream)
  • ansible-core has been updated to 2.18.1 (ee-minimal 2.18 stream)

Solution

Red Hat Ansible Automation Platform Execution Environments

Affected Products

  • Red Hat Ansible Automation Platform Text-Only Advisories for RHEL 8 x86_64

Fixes

  • BZ - 2325171 - CVE-2024-11079 ansible-core: Unsafe Tagging Bypass via hostvars Object in Ansible-Core

CVEs

  • CVE-2019-12900
  • CVE-2024-8775
  • CVE-2024-9902
  • CVE-2024-10041
  • CVE-2024-10963
  • CVE-2024-11079
  • CVE-2024-45296
  • CVE-2024-45801
  • CVE-2024-50602

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

ansible-automation-platform/ansible-builder-rhel8@sha256:a1988ba5bf65e42ac732e71b154323bf8df5fd25ce5a50b9dbaa1be370af62bb
ansible-automation-platform/ansible-builder-rhel9@sha256:017b6d52de4f1a8e7574b86d5fda0671ed2b784be3cf6fc683348df1167d2af3
ansible-automation-platform/ee-minimal-rhel8@sha256:3d39702e054b2fb712ace5cbc53d8b1619810240971e8046f5d0954e67c32880
ansible-automation-platform/ee-minimal-rhel8@sha256:9a792b2313c66057a1955809a845ff7fd6cbf5b8530d1b16e66c19843bf09fa3
ansible-automation-platform/ee-minimal-rhel8@sha256:0d26e5c3dfdddecd1fef6ed915b59e7f1269c199563d46c1f3dead813ec42499
ansible-automation-platform/ee-minimal-rhel8@sha256:b53ca6d71a7c8cc6ab889cc834d4cb5b3550545ef90c2a35b182eda11e4fab47
ansible-automation-platform/ee-minimal-rhel9@sha256:13f3527db21116ccabc95a90487a711208613991a5f2877ef0e24ef14d53542c
ansible-automation-platform/ee-minimal-rhel9@sha256:e97739f926c4fbf50b600b72d0e60964e18a79f0f12f40dd4f7752bfc580ab41
ansible-automation-platform/ee-minimal-rhel9@sha256:6b522fdad0e2d3f6cc838f5dcf8ba4534c3e0037da3cb8e7886d63724f5b5b2a
ansible-automation-platform/ee-minimal-rhel9@sha256:c1e98be6cbae19587bc52539765b009809084eba765f364a236e890f48bd0049

ppc64le

ansible-automation-platform/ansible-builder-rhel8@sha256:68a5232ec36bcd98049ca3d42fedf1a3c15667f260712c6e3e5b90c1877ebbce
ansible-automation-platform/ansible-builder-rhel9@sha256:1a8167f204602e8d31c4ff9a813a07840c72843dd7afa91dd52d511064550065
ansible-automation-platform/ee-minimal-rhel8@sha256:2946109032d00b8756175affc50fed01cc0bbcbc927a3fd2d5d846f825429b72
ansible-automation-platform/ee-minimal-rhel8@sha256:0a650301785be46f119a2080e7a09fefef893f611804a01b1304a28d98780fe0
ansible-automation-platform/ee-minimal-rhel8@sha256:db222c5e5b1e8783a14fe65d7cc11bb6222da908a41b193cc6949fec7e0ec6c0
ansible-automation-platform/ee-minimal-rhel8@sha256:e45a1b593ec7ae0808cc3d249696b5a5e16382dcd4294a6d969000c49848f34c
ansible-automation-platform/ee-minimal-rhel9@sha256:20b097862352178edce5ae8684e2ee441e8abdccdfe70aea26bc99b4817338bc
ansible-automation-platform/ee-minimal-rhel9@sha256:2e22d4c6a5cf8b66f4f2d55f8237f050b6611be0ab81dcf8de6bd4ed1af2882d
ansible-automation-platform/ee-minimal-rhel9@sha256:e313d9431a3a8b623fc928e1f12a445a00c334331841a210b6dc012e0fab108a
ansible-automation-platform/ee-minimal-rhel9@sha256:338dd71e8f2e5025e73e14ff97a936a9d74893add9358beb0497c7d041132352

s390x

ansible-automation-platform/ansible-builder-rhel8@sha256:d57bb670a115de96285e065ba0a4f2b67f752e8eec57e9b2f6371fbe3478972c
ansible-automation-platform/ansible-builder-rhel9@sha256:99e6443f9aacceff0df4131349e3fe89ece17a5ed1507bc1c74b9692d2853624
ansible-automation-platform/ee-minimal-rhel8@sha256:4b746a01c9dbd0c5ad07f085aa8236bbc93d21e7f1f5b9c395b8988b7703a01a
ansible-automation-platform/ee-minimal-rhel8@sha256:50cf5bbb57c9dfa77b385132948ea68cb20212df7476c94cc7087324ecf77254
ansible-automation-platform/ee-minimal-rhel8@sha256:44aae8b7c5fc7d0774962084a2943f567fbfdb740e31d1808be3da05a0c4049e
ansible-automation-platform/ee-minimal-rhel8@sha256:39169c112d66b9e7e9438c5246d1b25b8cf894aafc2880923472ad5c24b5d546
ansible-automation-platform/ee-minimal-rhel9@sha256:a3d23adb3b0c643fa16b91e71cc313c3908fff4ebf317568895b204b9416351f
ansible-automation-platform/ee-minimal-rhel9@sha256:2f763263c5252579c4106b6e8e7f030e092df6a24a4270c00084dd25939b3a04
ansible-automation-platform/ee-minimal-rhel9@sha256:c417b7b9097a7edaff2903769bff9ec275719f22acd1dfe0e812c26ae32a43f2
ansible-automation-platform/ee-minimal-rhel9@sha256:a64195114c059e7f49dbb19fc08eb9fe4e92e63d4e2f99e54fb83eac9860cc0f

x86_64

ansible-automation-platform/ansible-builder-rhel8@sha256:6b077737281691a1bfc90d1ae33fc30ce09a7c34240c1816aa2e678c0c0a91fa
ansible-automation-platform/ansible-builder-rhel8@sha256:06bccba7cd23ceff5c03ea32d80099cd2a3ce68b9c03435936cb4d6cfff4974c
ansible-automation-platform/ansible-builder-rhel9@sha256:006df4661ba4abe1c9166a696d5aed80ad2958b4fc0b675f13228c801585fe8d
ansible-automation-platform/ee-29-rhel8@sha256:03a835f116a9636bb4a03884b8686f6aa82a03374aa431ca02350dcbf40f5898
ansible-automation-platform/ee-minimal-rhel8@sha256:bf21c17ba56785bd920f3e4ec869a790d12ca9876b70dcb2be6a3f5cbfda2966
ansible-automation-platform/ee-minimal-rhel8@sha256:9313194b84341535a96f02257389a759c8c31f2f3922f44c5c373380901d9432
ansible-automation-platform/ee-minimal-rhel8@sha256:5e98ecd8212d3ec46e2ae13e51e6c7f181718b0332a54351a229bcea4ddc63fe
ansible-automation-platform/ee-minimal-rhel8@sha256:0b6a08e245cc02b03f5ae0b6fb74ac8f9738c437b4de3fa9a2b3225a2e914fda
ansible-automation-platform/ee-minimal-rhel8@sha256:6afae7906f7baccb28359493e832265d3f24f67fd4144246ddaf6e704512a8c2
ansible-automation-platform/ee-minimal-rhel8@sha256:5b411c45dec6c058ce918ebd9c37e1b9e6fbc9d3ec619b67cbfdf9c70d7033e5
ansible-automation-platform/ee-minimal-rhel8@sha256:db244d6b4f06ae97b9b15fe3071b7aab85daef71e5e92dc9d6459ce9903a37d2
ansible-automation-platform/ee-minimal-rhel9@sha256:ae770ba7ca5e0d9789fc85370fb887df5102542ee6463ab36a413b37e383cf0d
ansible-automation-platform/ee-minimal-rhel9@sha256:8afa6b37476e2bba2a00b61ba9a48da9cc1f22e7f182c5080bc873eaaa84b537
ansible-automation-platform/ee-minimal-rhel9@sha256:5fe58177f6c0ae204c3943c34febfaa41cd553819beee08543e30c922835cbbc
ansible-automation-platform/ee-minimal-rhel9@sha256:8270a2afb90b991005c830c5fa989a260c0e313d6cb6eaa40ab3f2e8b7df6072

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat X (formerly Twitter)

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility