Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r65-35qq-ch8j

Опубликовано: 04 мар. 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.8
CVSS3: 5.5

Описание

Ansible discloses sensitive information in traceback error message

Ansible is an IT automation system that handles configuration management, application deployment, cloud provisioning, ad-hoc task execution, network automation, and multi-node orchestration. A flaw was found in Ansible Engine's ansible-connection module where sensitive information, such as the Ansible user credentials, is disclosed by default in the traceback error message when Ansible receives an unexpected response from set_options. The highest threat from this vulnerability is confidentiality.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 2.9.27

2.9.27

EPSS

Процентиль: 46%
0.00228
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
redhat
около 4 лет назад

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
nvd
больше 3 лет назад

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 5.5
debian
больше 3 лет назад

A flaw was found in Ansible Engine's ansible-connection module, where ...

EPSS

Процентиль: 46%
0.00228
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-209