Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-7550

Опубликовано: 21 нояб. 2017
Источник: ubuntu
Приоритет: negligible
CVSS2: 5
CVSS3: 9.8

Описание

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

2.5.1+dfsg-1
devel

not-affected

2.6.1+dfsg-1
esm-apps/bionic

not-affected

2.5.1+dfsg-1
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
precise/esm

DNE

trusty

not-affected

code not present
trusty/esm

not-affected

code not present
upstream

released

2.4.2.0+dfsg-1

Показывать по

Ссылки на источники

5 Medium

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.5
redhat
больше 8 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 9.8
nvd
около 8 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 9.8
debian
около 8 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x bef ...

CVSS3: 9.8
github
больше 3 лет назад

Ansible Insertion of Sensitive Information into Log File vulnerability

suse-cvrf
почти 2 года назад

Security update for SUSE Manager Client Tools

5 Medium

CVSS2

9.8 Critical

CVSS3