Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pm48-cvv2-29q5

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

Ansible Uses Plugins That Disclose Credentials

Ansible, all ansible_engine-2.x versions and ansible_engine-3.x up to ansible_engine-3.5, was logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 2.6.20

2.6.20

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.7.0a1, < 2.7.14

2.7.14

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.8.0a1, < 2.8.6

2.8.6

EPSS

Процентиль: 36%
0.00153
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-117
CWE-532

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

CVSS3: 7.3
redhat
больше 6 лет назад

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

CVSS3: 7.8
nvd
больше 6 лет назад

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.

CVSS3: 7.8
debian
больше 6 лет назад

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, an ...

CVSS3: 5.5
fstec
больше 6 лет назад

Уязвимость системы управления конфигурациями Ansible, связана с раскрытием информации через регистрационные файлы, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 36%
0.00153
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-117
CWE-532