ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
2019-01-03T15:29:01.163
2024-11-21T03:53:30.457
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | ansible | < 2.5.14 | Yes |
Application | redhat | ansible | < 2.6.11 | Yes |
Application | redhat | ansible | < 2.7.5 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Application | redhat | ansible_engine | 2.0 | Yes |
Application | redhat | ansible_engine | 2.5 | Yes |
Application | redhat | ansible_engine | 2.6 | Yes |
Application | redhat | ansible_engine | 2.7 | Yes |
Application | redhat | openstack | 14 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |
Application | suse | package_hub | - | Yes |
Operating System | suse | linux_enterprise | 12.0 | No |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 19.04 | Yes |