MGASA-2018-0303

Source
https://advisories.mageia.org/MGASA-2018-0303.html
Import Source
https://advisories.mageia.org/MGASA-2018-0303.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0303
Related
Published
2018-07-01T17:17:14Z
Modified
2018-07-01T16:40:42Z
Summary
Updated ansible packages fix security vulnerability
Details

Ansible prior to 2.4.5 does not honor the nolog task flag for failed tasks. When the nolog flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible (CVE-2018-10855).

References
Credits

Affected packages

Mageia:6 / ansible

Package

Name
ansible
Purl
pkg:rpm/mageia/ansible?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.5.0-1.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / ansible

Package

Name
ansible
Purl
pkg:rpm/mageia/ansible?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.5.0-1.1.mga5

Ecosystem specific

{
    "section": "core"
}