Описание
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
ansible-core | fixed | 2.12.0-1 | package | |
ansible | fixed | 5.4.0-1 | package | |
ansible | fixed | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 | bullseye | package |
ansible | end-of-life | stretch | package | |
ansible-base | removed | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=1975767
https://github.com/ansible/ansible/commit/79e9dae29212a88aa60122ca6bd608947399017f
ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid
EPSS
Связанные уязвимости
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
Ansible discloses sensitive information in traceback error message
EPSS