Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 4 additions & 8 deletions downstream/titles/release-notes/async/aap-25-20250129.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -32,17 +32,17 @@ The following enhancements and bug fixes have been implemented in this release o

With this update, the following CVEs have been addressed:

* link:https://access.redhat.com/security/cve/cve-2024-56326[CVE-2024-56326] `python-jinja2`: Jinja has a sandbox breakout through indirect reference to format method.(AAP-38852)
* link:https://access.redhat.com/security/cve/cve-2024-56326[CVE-2024-56326] `python3.11-jinja2`: Jinja has a sandbox breakout through indirect reference to format method.(AAP-38852)

* CVE-2024-56374 `ansible-lightspeed-container`: Potential denial-of-service vulnerability in IPv6 validation.(AAP-38647)
* link:https://access.redhat.com/security/cve/CVE-2024-56374[CVE-2024-56374] `ansible-lightspeed-container`: Potential denial-of-service vulnerability in IPv6 validation.(AAP-38647)

* CVE-2024-56374 `python-django`: potential denial-of-service vulnerability in IPv6 validation.(AAP-38630)
* link:https://access.redhat.com/security/cve/CVE-2024-56374[CVE-2024-56374] `python3.11-django`: potential denial-of-service vulnerability in IPv6 validation.(AAP-38630)

* link:https://access.redhat.com/security/cve/cve-2024-53907[CVE-2024-53907] `python3.11-django`: Potential denial-of-service in django.utils.html.strip_tags().(AAP-38486)

* link:https://access.redhat.com/security/cve/cve-2024-56201[CVE-2024-56201] `python3.11-jinja2`: Jinja has a sandbox breakout through malicious filenames.(AAP-38331)

* CVE-2024-56374 `automation-controller`: Potential denial-of-service vulnerability in IPv6 validation.(AAP-38648)
* link:https://access.redhat.com/security/cve/CVE-2024-56374[CVE-2024-56374] `automation-controller`: Potential denial-of-service vulnerability in IPv6 validation.(AAP-38648)

* link:https://access.redhat.com/security/cve/cve-2024-56201[CVE-2024-56201] `automation-controller`: Jinja has a sandbox breakout through malicious filenames.(AAP-38081)

Expand All @@ -56,10 +56,6 @@ With this update, the following CVEs have been addressed:

* Fixed an issue where an actively running job on an execution node may have had its folder deleted by a system task. This fix addresses some *Failed to JSON parse a line from worker stream* type errors.(AAP-38137)

* Fixed an issue where deprecation errors on CI checks in {ControllerName} were not ignored.(AAP-36522)

* Fixed an issue where sanity tests were failing on the latest version {ControllerName}.(AAP-36516)



=== Container-based {PlatformNameShort}
Expand Down