Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-588w-w6mv-3cw5

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Ansible Insertion of Sensitive Information into Log File vulnerability

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.4.0.0, < 2.4.1.0

2.4.1.0

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.3.0.0, < 2.3.3.0

2.3.3.0

EPSS

Процентиль: 88%
0.0356
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 8.5
redhat
почти 9 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 9.8
nvd
почти 9 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 9.8
debian
почти 9 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x bef ...

suse-cvrf
больше 2 лет назад

Security update for SUSE Manager Client Tools

EPSS

Процентиль: 88%
0.0356
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-532