PT-2017-17794 · Red Hat+2 · Ansible+2
Abadger
·
Publicado
2017-11-02
·
Atualizado
2026-06-03
·
CVE-2017-7550
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ansible versions 2.3.x through 2.3.2
Ansible versions 2.4.x through 2.4.0
Description
A flaw was found in the way Ansible passed certain parameters to the jenkins plugin module, allowing remote attackers to expose sensitive information from a remote host's logs. The issue was resolved by not allowing passwords to be specified in the
params argument.Recommendations
For Ansible versions 2.3.x through 2.3.2, update to version 2.3.3 or later.
For Ansible versions 2.4.x through 2.4.0, update to version 2.4.1 or later.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Ansible
Ansible-Core