Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-7550

Опубликовано: 21 нояб. 2017
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 5
CVSS3: 9.8

Описание

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

2.5.1+dfsg-1
devel

not-affected

2.6.1+dfsg-1
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

2.5.1+dfsg-1
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
precise/esm

DNE

trusty

not-affected

code not present
trusty/esm

not-affected

code not present

Показывать по

Ссылки на источники

EPSS

Процентиль: 88%
0.0356
Низкий

5 Medium

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.5
redhat
почти 9 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 9.8
nvd
почти 9 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

CVSS3: 9.8
debian
почти 9 лет назад

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x bef ...

CVSS3: 9.8
github
больше 4 лет назад

Ansible Insertion of Sensitive Information into Log File vulnerability

suse-cvrf
больше 2 лет назад

Security update for SUSE Manager Client Tools

EPSS

Процентиль: 88%
0.0356
Низкий

5 Medium

CVSS2

9.8 Critical

CVSS3