QID 239680

Date Published: 2021-10-20

QID 239680: Red Hat Update for Ansible (RHSA-2021:3871)

Ansible is a simple model-driven configuration management, multi-nodedeployment, and remote-task execution system. Solution For details on how to apply this update, which includes the changesdescribed in this advisory, refer to:https://access.redhat.com/articles/11258 Affected Products Red Hat Ansible Engine 2.9 for RHEL 8 x86_64 Red Hat Ansible Engine 2.9 for RHEL 8 s390x Red Hat Ansible Engine 2.9 for RHEL 8 ppc64le Red Hat Ansible Engine 2.9 for RHEL 8 aarch64 Red Hat Ansible Engine 2.9 for RHEL 7 x86_64 Red Hat Ansible Engine 2.9 for RHEL 7 s390x Red Hat Ansible Engine 2.9 for RHEL 7 ppc64le Fixes BZ - 1975767 - CVE-2021-3620 Ansible: ansible-connection module discloses sensitive info in traceback error message CVEs CVE-2021-3620 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name

Affected Products:

Red Hat Ansible Engine 2.9 for RHEL 8 x86_64
Red Hat Ansible Engine 2.9 for RHEL 8 s390x
Red Hat Ansible Engine 2.9 for RHEL 8 ppc64le
Red Hat Ansible Engine 2.9 for RHEL 8 aarch64
Red Hat Ansible Engine 2.9 for RHEL 7 x86_64
Red Hat Ansible Engine 2.9 for RHEL 7 s390x
Red Hat Ansible Engine 2.9 for RHEL 7 ppc64le

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to Applying Package Updates to RHEL system for details.

    Refer to Red Hat security advisory RHSA-2021:3871 to address this issue and obtain more information.

    Vendor References

    CVEs related to QID 239680

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2021:3871 Red Hat Enterprise Linux URL Logo access.redhat.com/errata/RHSA-2021:3871?language=en