Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10855

Опубликовано: 11 июн. 2018
Источник: redhat
CVSS3: 5.9

Описание

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

Отчет

Red Hat Gluster Storage 3 and Red Hat Ceph Storage 3 ships the affected version of ansible, but they no longer maintain their own version of ansible. Both the products will consume fixes directly from ansible repository.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2ansibleAffected
Red Hat Ceph Storage 3ansibleAffected
Red Hat OpenShift Enterprise 3ansibleNot affected
Red Hat Quickstart Cloud Installer 1ansibleWill not fix
Red Hat Satellite 6ansibleWill not fix
Red Hat Storage 3ansibleAffected
CloudForms Management Engine 5.9ansibleFixedRHSA-2018:218412.07.2018
CloudForms Management Engine 5.9ansible-towerFixedRHSA-2018:218412.07.2018
CloudForms Management Engine 5.9cfmeFixedRHSA-2018:218412.07.2018
CloudForms Management Engine 5.9cfme-amazon-smartstateFixedRHSA-2018:218412.07.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1588855ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

CVSS3: 5.9
nvd
больше 7 лет назад

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

CVSS3: 5.9
debian
больше 7 лет назад

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the n ...

CVSS3: 5.9
github
больше 7 лет назад

Ansible exposes sensitive data in log files and on the terminal

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная c некорректной обработкой опции no_log, позволяющая нарушителю получить несанкционированный доступ к информации

5.9 Medium

CVSS3