(RHSA-2025:4553) Moderate: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Discription

image
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): automation-controller: Potential denial-of-service vulnerability in django.utils.text.wrap() (CVE-2025-26699) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Updates and fixes included: Automation Platform * Refactored the authenticate() method inside the AuthenticatorPlugin class in legacy_password.py and legacy_sso.py to their common parent LegacyMixin. Added comments to classes and their methods for code clarity (AAP-44460) * Allow gateway to be installed with a different name for the admin user (AAP-44180) * Added a grpc_defaults.py file which can contain override information for the GRPC server settings (AAP-44176) * Changed anchor tag on api html view to button tag so that it doesn't violate semantic rules (AAP-43802) * Fixed how exceptions are handled on SSO login allowing for error messages to be…Read More

Back to Main

Subscribe for the latest news: