StackRadar

CVE-2024-9902

Medium

Advisory

Published 6 Nov 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
1 of 2
affected packages

ansible-core Incorrect Authorization vulnerability

Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
ansible-corepypi2.14.5, 2.15.3, 2.15.6, 2.15.82.14.18rc1, 2.15.13rc14
ansibledeb2.5.3-1ppa~trustyno fix listed2
OSV records
GHSA-32p4-gm2c-wmchUBUNTU-CVE-2024-9902
Also known as
PYSEC-2026-1121

Charts affected

5 by stars
ChartLatestAffected imagesRadar Score
awx-operatorawx-operator-helm3.2.11 of 2See more

awx-operator awx-operator-helm 3.2.1

1 of the 2 container images this version deploys carry CVE-2024-9902.

Container imageDigestPackageFixed in
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
ansible-core@2.15.8
2.15.13rc1

Open the chart page →

9,868
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2024-9902.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
ansible@2.5.3-1ppa~trusty
no fix listed
galaxy/galaxy-stable:v18.018e577a626dfd
ansible@2.5.3-1ppa~trusty
no fix listed

Open the chart page →

70,895
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2024-9902.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
ansible-core@2.15.3
2.15.13rc1

Open the chart page →

12,754
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-9902.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
ansible-core@2.14.5
2.14.18rc1

Open the chart page →

3,337
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-9902.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
ansible-core@2.15.6
2.15.13rc1

Open the chart page →

18,756

Container images carrying it

6 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
galaxy/galaxy-init:v18.010267bad550e6
ansible@2.5.3-1ppa~trusty
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
ansible@2.5.3-1ppa~trusty
no fix listed
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
ansible-core@2.15.3
2.15.13rc1
1
semaphoreui/semaphore:v2.9.645b50bc11833f
ansible-core@2.14.5
2.14.18rc1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
ansible-core@2.15.6
2.15.13rc1
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
ansible-core@2.15.8
2.15.13rc1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.