Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-923p-fr2c-g5m2

Опубликовано: 07 апр. 2021
Источник: github
Github: Прошло ревью
CVSS4: 2.4
CVSS3: 3.9

Описание

Exposure of Sensitive Information to an Unauthorized Actor in Ansible

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 2.7.17

2.7.17

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.8.0a1, < 2.8.11

2.8.11

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.9.0a1, < 2.9.7

2.9.7

EPSS

Процентиль: 14%
0.00045
Низкий

2.4 Low

CVSS4

3.9 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.9
ubuntu
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS3: 3.9
redhat
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS3: 3.9
nvd
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

CVSS3: 3.9
debian
почти 6 лет назад

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9 ...

CVSS3: 3.9
fstec
почти 6 лет назад

Уязвимость модуля svn системы управления конфигурациями Ansible, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

EPSS

Процентиль: 14%
0.00045
Низкий

2.4 Low

CVSS4

3.9 Low

CVSS3

Дефекты

CWE-200