Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5rrg-rr89-x9mv

Опубликовано: 25 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Ansible Exposes Sensitive Information

A flaw was found in the Ansible Engine prior to 2.10.6rc1, 2.9.18rc1, and 2.8.19rc1, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.10.0a1, < 2.10.6rc1

2.10.6rc1

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.9.0a1, < 2.9.18rc1

2.9.18rc1

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 2.8.19rc1

2.8.19rc1

EPSS

Процентиль: 36%
0.00149
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200
CWE-522

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5
redhat
около 5 лет назад

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
nvd
почти 5 лет назад

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
msrc
больше 4 лет назад

A flaw was found in the Ansible Engine 2.9.18 where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
debian
почти 5 лет назад

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is ...

EPSS

Процентиль: 36%
0.00149
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200
CWE-522