Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j667-c2hm-f2wp

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.8
CVSS3: 5.5

Описание

Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 2.8.14

2.8.14

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.9.0a1, < 2.9.12

2.9.12

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.10.0a1, < 2.10.1rc2

2.10.1rc2

EPSS

Процентиль: 36%
0.00149
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-117
CWE-532

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
redhat
больше 5 лет назад

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
nvd
больше 5 лет назад

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
debian
больше 5 лет назад

A flaw was found in the Ansible Engine when using module_args. Tasks e ...

CVSS3: 5.5
fstec
больше 5 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с неправильной обработкой выходных данных для журналов регистрации, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 36%
0.00149
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-117
CWE-532