CVE-2024-11079: Red Hat Ansible Automation Platform Execution Environments
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.
Affected products
- Red Hat Ansible Automation Platform Execution Environments: before 1.2.0-93 (fixed in 1.2.0-93); before 3.0.1-108 (fixed in 3.0.1-108); before 2.9.27-34 (fixed in 2.9.27-34); before 2.12.10-56 (fixed in 2.12.10-56); before 2.15.13-4 (fixed in 2.15.13-4)
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 1:2.16.14-1.el8ap (fixed in 1:2.16.14-1.el8ap)
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 1:2.16.14-1.el9ap (fixed in 1:2.16.14-1.el9ap)
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux Ai Rhel Ai
Published 2024-11-12. Last modified 2026-06-30.