This update for ansible fixes the following issues:
Security vulnerabilities fixed:
- CVE-2018-16876: Respect no_log on retry and high verbosity (bsc#1118896)
- CVE-2018-16859: Windows - prevent sensitive content from appearing in
scriptblock logging (bsc#1116587)
- CVE-2018-10855: Fixed the honouration of the no_log option with failed
task iterations (boo#1097775)
- CVE-2017-7466: Fixed an input validation vulnerability in Ansible's
handling
of data sent from client systems
- CVE-2017-7481: Fixed a security issue with lookup return not tainting
the jinja2 environment (bsc#1038785)
Other bug fixes and changes:
- Update to version 2.7.6
* Added log message at -vvvv when using netconf connection listing
connection details.
* Changes how ansible-connection names socket lock files. They now use
the same name as the socket itself, and as such do not lock other
attempts on connections to the same host,...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15:
zypper in -t patch openSUSE-2019-238=1
- openSUSE Backports SLE-15 (noarch):
ansible-2.7.6-bp150.3.3.1
https://www.suse.com/security/cve/CVE-2017-7466.html
https://www.suse.com/security/cve/CVE-2017-7481.html
https://www.suse.com/security/cve/CVE-2018-10855.html
https://www.suse.com/security/cve/CVE-2018-10875.html
https://www.suse.com/security/cve/CVE-2018-16859.html
https://www.suse.com/security/cve/CVE-2018-16876.html
https://bugzilla.suse.com/1056094
https://bugzilla.suse.com/1097775
--
Get the latest Linux and open source security news straight to your inbox.