Exposure of sensitive information in Ansible vault files due to improper logging. (CVE-2024-8775) Ansible-core user may read/write unauthorized content. (CVE-2024-9902) Unsafe tagging bypass via hostvars object in ansible-core. (CVE-2024-11079) . MGASA-2025-0052 - Updated python-ansible-core packages fix security vulnerabilities Publication date: 12 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0052.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-8775, CVE-2024-9902, CVE-2024-11079 Exposure of sensitive information in Ansible vault files due to improper logging. (CVE-2024-8775) Ansible-core user may read/write unauthorized content. (CVE-2024-9902) Unsafe tagging bypass via hostvars object in ansible-core. (CVE-2024-11079) References: - https://bugs.mageia.org/show_bug.cgi?id=33828 - - https://www.cve.org/CVERecord?id=CVE-2024-8775 - https://www.cve.org/CVERecord?id=CVE-2024-9902 - https://www.cve.org/CVERecord?id=CVE-2024-11079 SRPMS: - 9/core/python-ansible-core-2.14.18-1.mga9 . Software-ansible-updates address security flaws that risk leaking private data, enhancing protection for users.. ansible, security updates, mageia security, python packages. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.