Описание
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
A flaw was discovered in the way Ansible templating was implemented, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5 | ansible | Out of support scope | ||
| Red Hat Ansible Tower 3 | ansible | Affected | ||
| Red Hat Ceph Storage 2 | ansible | Affected | ||
| Red Hat Ceph Storage 3 | ansible | Affected | ||
| Red Hat Enterprise Linux 7 | ansible | Will not fix | ||
| Red Hat OpenShift Container Platform 3.2 | ansible | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.3 | ansible | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.4 | ansible | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.5 | ansible | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.6 | ansible | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
4.6 Medium
CVSS3
Связанные уязвимости
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
A flaw was discovered in the way Ansible templating was implemented in ...
Exposure of Sensitive Information to an Unauthorized Actor in ansible
Уязвимость системы управления конфигурациями ansible, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность
EPSS
4.6 Medium
CVSS3