The user module leaked parameters passed to ssh-keygen to the process
environment (CVE-2018-16837).
The fetch module was susceptible to path traversal (CVE-2019-3828).
- https://bugs.mageia.org/show_bug.cgi?id=24395
- https://lists.debian.org/debian-security-announce/2019/msg00037.html
- https://www.cve.org/CVERecord?id=CVE-2019-3828
- 6/core/ansible-2.4.6.0-1.3.mga6
Get the latest Linux and open source security news straight to your inbox.