Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8 MGASA-2021-0132 Moderate: Ansible Data Leak Risks

mageia
Calendar Grey March 11, 2021
Dist Mageia Esm H88
Enhanced Ansible updates address severe vulnerabilities in Mageia advisory MGASA-2021-0132, bolstering user information security.
User data leak in snmp_facts module (CVE-2021-20178)

Summary

User data leak in snmp_facts module (CVE-2021-20178).
The bitbucket_pipeline_variable module exposed secured values (CVE-2021-20180).
Multiple collections exposed secured values (CVE-2021-20191).
In basic.py, no_log with fallback option (CVE-2021-20228).
The ansible package has been updated to version 2.9.18, fixing these issues and other bugs.

References

- https://bugs.mageia.org/show_bug.cgi?id=28436

- https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst#id64

- https://access.redhat.com/errata/RHSA-2021:0664

- https://www.cve.org/CVERecord?id=CVE-2021-20178

- https://www.cve.org/CVERecord?id=CVE-2021-20180

- https://www.cve.org/CVERecord?id=CVE-2021-20191

- https://www.cve.org/CVERecord?id=CVE-2021-20228

Resolution

SRPMS

- 8/core/ansible-2.9.18-1.mga8

Publication date: 12 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0132.html
Type: security
CVE: CVE-2021-20178, CVE-2021-20180, CVE-2021-20191, CVE-2021-20228

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here