Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 39: FEDORA-2024-0d894565a0 Critical: Mitigating Info Leak in Ansible

fedora
Calendar Grey January 24, 2024
Dist Fedora Esm H88
This update resolves CVE-2024-0692 in ansible-core for Fedora 40, improving the safety of task handling.
Mitigate CVE-2024-0690

Summary

Ansible is a radically simple model-driven configuration management,

multi-node deployment, and remote task execution system. Ansible works

over SSH and does not require any software or daemons to be installed

on remote nodes. Extension modules can be written in any language and

are transferred to managed machines automatically.

This is the base part of ansible (the engine).

Update Information:

Mitigate CVE-2024-0690

Change Log

* Thu Jan 18 2024 Maxwell G - 2.16.2-2 - Mitigate CVE-2024-0690.

References


[ 1 ] Bug #2259021 - CVE-2024-0690 ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2259021

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0d894565a0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ansible-core
Product: Fedora 39
Version: 2.16.2
Release: 2.fc39
Summary: A radically simple IT automation system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here