PT-2017-17794 · Red Hat+2 · Ansible+2
Abadger
·
Published
2017-11-02
·
Updated
2026-06-03
·
CVE-2017-7550
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ansible versions 2.3.x through 2.3.2
Ansible versions 2.4.x through 2.4.0
Description
A flaw was found in the way Ansible passed certain parameters to the jenkins plugin module, allowing remote attackers to expose sensitive information from a remote host's logs. The issue was resolved by not allowing passwords to be specified in the
params argument.Recommendations
For Ansible versions 2.3.x through 2.3.2, update to version 2.3.3 or later.
For Ansible versions 2.4.x through 2.4.0, update to version 2.4.1 or later.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ansible
Ansible-Core