Описание
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
A flaw was found in the way Ansible passed certain parameters to the jenkins_plugin module. A remote attacker could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
Отчет
Red Hat OpenStack Platform will no longer be updating the Ansible package in:
- Red Hat OpenStack Platform 10 (Newton)
- Red Hat OpenStack Platform 11 (Ocata) As of Red Hat Enterprise Linux 7.4, customers can consume an updated Ansible package directly from the extras-rhel-7.4 channel. For more information, refer to Red Hat Enterprise Linux release information.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Enterprise 3 | ansible | Not affected | ||
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | ||
| Red Hat OpenStack Platform 11 (Ocata) | ansible | Will not fix | ||
| Red Hat OpenStack Platform 12 (Pike) | ansible | Will not fix | ||
| Red Hat Quickstart Cloud Installer 1 | ansible | Under investigation | ||
| Red Hat Storage 3 | ansible | Will not fix | ||
| Red Hat Storage Console 2 | ansible | Will not fix | ||
| Red Hat Enterprise Linux 7 Extras | ansible | Fixed | RHSA-2017:2966 | 19.10.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.5 High
CVSS3
Связанные уязвимости
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x bef ...
Ansible Insertion of Sensitive Information into Log File vulnerability
EPSS
8.5 High
CVSS3