Vulnerability Database
Blog
FAQ
Docs
RHSA-2025:0340
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2025:0340
Import Source
https://security.access.redhat.com/data/osv/RHSA-2025:0340.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2025:0340
Related
CVE-2024-11407
CVE-2024-52304
CVE-2024-53907
CVE-2024-53908
CVE-2024-55565
Published
2025-01-16T10:02:24Z
Modified
2025-01-16T10:02:24Z
Severity
9.1 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Details
References
https://access.redhat.com/errata/RHSA-2025:0340
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=2327130
https://bugzilla.redhat.com/show_bug.cgi?id=2329003
https://bugzilla.redhat.com/show_bug.cgi?id=2329287
https://bugzilla.redhat.com/show_bug.cgi?id=2329288
https://bugzilla.redhat.com/show_bug.cgi?id=2331063
https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0340.json
https://access.redhat.com/security/cve/CVE-2024-11407
https://www.cve.org/CVERecord?id=CVE-2024-11407
https://nvd.nist.gov/vuln/detail/CVE-2024-11407
https://github.com/grpc/grpc/commit/e9046b2bbebc0cb7f5dc42008f807f6c7e98e791
https://access.redhat.com/security/cve/CVE-2024-52304
https://www.cve.org/CVERecord?id=CVE-2024-52304
https://nvd.nist.gov/vuln/detail/CVE-2024-52304
https://github.com/aio-libs/aiohttp/commit/259edc369075de63e6f3a4eaade058c62af0df71
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-8495-4g3g-x7pr
https://access.redhat.com/security/cve/CVE-2024-53907
https://www.cve.org/CVERecord?id=CVE-2024-53907
https://nvd.nist.gov/vuln/detail/CVE-2024-53907
https://www.djangoproject.com/weblog/2024/dec/04/security-releases/
https://access.redhat.com/security/cve/CVE-2024-53908
https://www.cve.org/CVERecord?id=CVE-2024-53908
https://nvd.nist.gov/vuln/detail/CVE-2024-53908
https://access.redhat.com/security/cve/CVE-2024-55565
https://www.cve.org/CVERecord?id=CVE-2024-55565
https://nvd.nist.gov/vuln/detail/CVE-2024-55565
https://github.com/ai/nanoid/compare/3.3.7...3.3.8
https://github.com/ai/nanoid/pull/510
https://github.com/ai/nanoid/releases/tag/5.0.9
Affected packages
Red Hat:ansible_automation_platform_developer:2.5::el8
/
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.6-1.el8ap
Red Hat:ansible_automation_platform:2.5::el8
/
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.6-1.el8ap
Red Hat:ansible_automation_platform_developer:2.5::el9
/
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.6-1.el9ap
Red Hat:ansible_automation_platform:2.5::el9
/
automation-controller-venv-tower
Package
Name
automation-controller-venv-tower
Purl
pkg:rpm/redhat/automation-controller-venv-tower
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.6.6-1.el9ap
Red Hat:ansible_automation_platform:2.5::el8
/
python3.11-aiohttp
Package
Name
python3.11-aiohttp
Purl
pkg:rpm/redhat/python3.11-aiohttp
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.10.11-1.el8ap
Red Hat:ansible_automation_platform:2.5::el8
/
python3.11-aiohttp-debuginfo
Package
Name
python3.11-aiohttp-debuginfo
Purl
pkg:rpm/redhat/python3.11-aiohttp-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.10.11-1.el8ap
Red Hat:ansible_automation_platform:2.5::el8
/
python3.11-aiohttp-debugsource
Package
Name
python3.11-aiohttp-debugsource
Purl
pkg:rpm/redhat/python3.11-aiohttp-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.10.11-1.el8ap
Red Hat:ansible_automation_platform:2.5::el9
/
python3.11-aiohttp
Package
Name
python3.11-aiohttp
Purl
pkg:rpm/redhat/python3.11-aiohttp
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.10.11-1.el9ap
Red Hat:ansible_automation_platform:2.5::el9
/
python3.11-aiohttp-debuginfo
Package
Name
python3.11-aiohttp-debuginfo
Purl
pkg:rpm/redhat/python3.11-aiohttp-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.10.11-1.el9ap
Red Hat:ansible_automation_platform:2.5::el9
/
python3.11-aiohttp-debugsource
Package
Name
python3.11-aiohttp-debugsource
Purl
pkg:rpm/redhat/python3.11-aiohttp-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.10.11-1.el9ap
Red Hat:ansible_automation_platform:2.5::el8
/
automation-gateway-server
Package
Name
automation-gateway-server
Purl
pkg:rpm/redhat/automation-gateway-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.5.20250115-1.el8ap
Red Hat:ansible_automation_platform:2.5::el9
/
automation-gateway-server
Package
Name
automation-gateway-server
Purl
pkg:rpm/redhat/automation-gateway-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.5.20250115-1.el9ap
RHSA-2025:0340 - OSV