ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration (CVE-2024-0690) References: . MGASA-2024-0239 - Updated python-ansible-core packages fix security vulnerability Publication date: 25 Jun 2024 URL: https://advisories.mageia.org/MGASA-2024-0239.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-0690 ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration (CVE-2024-0690) References: - https://bugs.mageia.org/show_bug.cgi?id=33171 - https://lwn.net/Articles/971689/ - https://www.cve.org/CVERecord?id=CVE-2024-0690 SRPMS: - 9/core/python-ansible-core-2.14.17-1.1.mga9 . Recent updates to the python-ansible-core package address a critical vulnerability concerning information exposure in Mageia 9. Discover additional details.. python package update, security advisory Mageia, ansible core vulnerability, Ansible configuration issue. . Severity: Critical. LinuxSecurity.com Team
In Horde Groupware, there has been an XSS vulnerability in two components via the Color field in a Create Task List action. For Debian 9 stretch, this problem has been fixed in version . -------------------------------------------------------------------------Debian LTS Advisory DLA-2349-1
In Horde Groupware, there has been an XSS vulnerability in two components via the Color field in a Create Task List action. For Debian 9 stretch, this problem has been fixed in version . -------------------------------------------------------------------------Debian LTS Advisory DLA-2348-1
**nag 4.2.19** * [mjr] SECURITY: Fix multiple XSS vulnerabilities when displaying and filtering task lists.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-8ab75bcc08 2018-10-30 17:13:37.315955 --------------------------------------------------------------------------------Name : php-horde-nag Product : Fedora 29 Version : 4.2.19 Release : 1.fc29 URL : https://www.horde.org/apps/nag Summary : A web based task list manager Description : Nag is a web-based application built upon the Horde Application Framework which provides a simple, clean interface for managing online task lists (i.e., todo lists). It also includes strong integration with the other Horde applications and allows users to share task lists or enable light-weight project management. --------------------------------------------------------------------------------Update Information: **nag 4.2.19** * [mjr] SECURITY: Fix multiple XSS vulnerabilities when displaying and filtering task lists. --------------------------------------------------------------------------------ChangeLog: * Sat Sep 29 2018 Remi Collet - 4.2.19-1 - update to 4.2.19 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-8ab75bcc08' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
**nag 4.2.17** * [jan] SECURITY: Fix unauthorized access to task exports. * [jan] Fix regression when exporting single tags to iCalendar CATEGORIES. * [jan] Officially support PHP 7.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-f14c38d58f 2017-09-30 05:49:53.951070 --------------------------------------------------------------------------------Name : php-horde-nag Product : Fedora 25 Version : 4.2.17 Release : 1.fc25 URL : https://www.horde.org/apps/nag Summary : A web based task list manager Description : Nag is a web-based application built upon the Horde Application Framework which provides a simple, clean interface for managing online task lists (i.e., todo lists). It also includes strong integration with the other Horde applications and allows users to share task lists or enable light-weight project management. --------------------------------------------------------------------------------Update Information: **nag 4.2.17** * [jan] SECURITY: Fix unauthorized access to task exports. * [jan] Fix regression when exporting single tags to iCalendar CATEGORIES. * [jan] Officially support PHP 7. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade php-horde-nag' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
**nag 4.2.15** * [jan] SECURITY: Fix open redirects. * [mjr] Fix handling of delayed start dates (Bug #14634).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-d1c86c61f2 2017-08-10 15:18:13.065882 --------------------------------------------------------------------------------Name : php-horde-nag Product : Fedora 26 Version : 4.2.15 Release : 1.fc26 URL : https://www.horde.org/apps/nag Summary : A web based task list manager Description : Nag is a web-based application built upon the Horde Application Framework which provides a simple, clean interface for managing online task lists (i.e., todo lists). It also includes strong integration with the other Horde applications and allows users to share task lists or enable light-weight project management. --------------------------------------------------------------------------------Update Information: **nag 4.2.15** * [jan] SECURITY: Fix open redirects. * [mjr] Fix handling of delayed start dates (Bug #14634). --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade php-horde-nag' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.