Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia 6: MGASA-2019-0023 Critical: Ansible Sensitive Data Exposure

mageia
Calendar Grey January 8, 2019
Dist Mageia Esm H88
MGASA-2019-0023 - Updated ansible package fixes security vulnerability Publication date: 08 Jan 2019
It was found that when a retry task in ansible run with -vvv fails, it will log the raw return code, stdout and stderr from ssh which could have contained sensitive data (CVE-2018-...

Summary

It was found that when a retry task in ansible run with -vvv fails, it will log the raw return code, stdout and stderr from ssh which could have contained sensitive data (CVE-2018-16876).

References

- https://bugs.mageia.org/show_bug.cgi?id=24065

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ZDHLHZ5V5K5AKBTGPLGFTPK3YNSOC4FY/

- https://www.cve.org/CVERecord?id=CVE-2018-16876

Resolution

SRPMS

- 6/core/ansible-2.4.6.0-1.2.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 08 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0023.html
Type: security
CVE: CVE-2018-16876

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here