Hello. CVE-2016-8614 is marked as "no-dsa (can be fixed via point release)" for Jessie. But I think its *not affecting* Jessie as the vulnerable code present in separate module which only merged to ansible from version 2.3. I am going to mark it as *not-affected*. Let me know if my research is wrong.
--abhijith