Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7550

Опубликовано: 21 нояб. 2017
Источник: debian
EPSS Низкий

Описание

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed2.4.2.0+dfsg-1package

Примечания

  • https://github.com/ansible/ansible/issues/30874

  • https://github.com/ansible/ansible/pull/30875

  • Just an insecure example

EPSS

Процентиль: 71%
0.00675
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 8.5
redhat
больше 8 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 9.8
nvd
около 8 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 9.8
github
больше 3 лет назад

Ansible Insertion of Sensitive Information into Log File vulnerability

suse-cvrf
почти 2 года назад

Security update for SUSE Manager Client Tools

EPSS

Процентиль: 71%
0.00675
Низкий