Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7473

Опубликовано: 11 апр. 2017
Источник: redhat
CVSS3: 4.7

Описание

Ansible versions 2.2.3 and earlier are vulnerable to an information disclosure flaw due to the interaction of call back plugins and the no_log directive (information may not be sanitized properly).

Отчет

Ansible Security Team and Red Hat Product Security determined that this is not a vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ansibleUnder investigation
Red Hat OpenShift Enterprise 3ansibleAffected
Red Hat OpenStack Platform 10 (Newton)ansibleWill not fix
Red Hat OpenStack Platform 11 (Ocata)ansibleWill not fix
Red Hat Storage 3ansibleWill not fix
Red Hat Storage Console 2ansibleWill not fix

Показывать по

Дополнительная информация

Дефект:
CWE-212
https://bugzilla.redhat.com/show_bug.cgi?id=1440912ansible: Potential information disclosure via no_log directive

4.7 Medium

CVSS3

Связанные уязвимости

ubuntu
больше 8 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA based off of CNT 3. Further investigation determined that there was a secure method for using the directive. Notes: none.

nvd
больше 8 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA based off of CNT 3. Further investigation determined that there was a secure method for using the directive. Notes: none.

4.7 Medium

CVSS3