VDB
BDU%3A2025-09015
BDU%3A2025-09015
PUBLISHED
CVSS 5.5 MEDIUM
Уязвимость системы управления конфигурациями Ansible, связанная с неправильной проверкой входных данных, позволяющая нарушителю обойти существующие ограничения безопасности
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) | |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 1:2.16.14-1.el9ap |
| Red Hat | Ansible Automation Platform Execution Environments | 3.0.1-108 |
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) | |
| Red Hat | Ansible Automation Platform Execution Environments | 3.0.1-107 |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 1:2.16.14-1.el8ap |
| Red Hat | Ansible Automation Platform Execution Environments | 2.16.14-2 |
| Red Hat | Ansible Automation Platform Execution Environments | 2.17.7-1 |
| Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», Red Hat Inc., Ansible | openSUSE Tumbleweed, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Red Hat Enterprise Linux AI, Red Hat Enterprise Linux, Ansible Engine, Ansible Automation Platform Execution Environments, Ansible Automation Platform | |
| 0 | ||
| Red Hat | Ansible Automation Platform Execution Environments | 2.9.27-34 |
| Red Hat | Red Hat Enterprise Linux 10 |
Timeline
- Nov 11, 2024 CVE Published
- Nov 11, 2024 PoC Published
- Nov 12, 2024 PoC Published
- Mar 14, 2025 PoC Published
- Feb 16, 2026 CVE Updated
- Mar 22, 2026 Distribution Patch
- Mar 22, 2026 Security Advisory
- Jun 6, 2026 Distribution Patch
- Jun 6, 2026 Security Advisory
References
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-0811SE18 url
- https://access.redhat.com/errata/RHSA-2024:11145 advisory
- https://access.redhat.com/security/cve/cve-2024-11079 advisory
- https://www.suse.com/security/cve/CVE-2024-11079.html advisory
- RHSA-2024:10770 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-11079 vdb
- RHBZ#2325171 issue
- https://lists.debian.org/debian-lts-announce/2026/03/msg00006.html url
- https://github.com/advisories/GHSA-99w6-3xph-cx78 url
- https://redos.red-soft.ru/support/secure/ url
- https://wiki.astralinux.ru/astra-linux-se38-bulletin-2026-0126SE38 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://security-tracker.debian.org/tracker/CVE-2024-11079 advisory