Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-588w-w6mv-3cw5

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Ansible Insertion of Sensitive Information into Log File vulnerability

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.4.0.0, < 2.4.1.0

2.4.1.0

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.3.0.0, < 2.3.3.0

2.3.3.0

EPSS

Процентиль: 71%
0.00675
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 8.5
redhat
больше 8 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 9.8
nvd
около 8 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 9.8
debian
около 8 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x bef ...

suse-cvrf
почти 2 года назад

Security update for SUSE Manager Client Tools

EPSS

Процентиль: 71%
0.00675
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-532