QID 981347

QID 981347: Python (pip) Security Update for ansible (GHSA-grgm-pph5-j5h7)

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    Customers are advised to refer to GHSA-grgm-pph5-j5h7 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981347

    Software Advisories
    Advisory ID Software Component Link
    GHSA-grgm-pph5-j5h7 ansible URL Logo github.com/advisories/GHSA-grgm-pph5-j5h7