Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwcc-j78w-j73w

Опубликовано: 10 окт. 2018
Источник: github
Github: Прошло ревью
CVSS4: 8.2
CVSS3: 5.9

Описание

Ansible exposes sensitive data in log files and on the terminal

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.5.0a1, < 2.5.5

2.5.5

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.4.0.0, < 2.4.5.0

2.4.5.0

EPSS

Процентиль: 87%
0.03372
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

CVSS3: 5.9
redhat
больше 7 лет назад

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

CVSS3: 5.9
nvd
больше 7 лет назад

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

CVSS3: 5.9
debian
больше 7 лет назад

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the n ...

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная c некорректной обработкой опции no_log, позволяющая нарушителю получить несанкционированный доступ к информации

EPSS

Процентиль: 87%
0.03372
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-532