QID 981353
QID 981353: Python (pip) Security Update for ansible (GHSA-jwcc-j78w-j73w)
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jwcc-j78w-j73w for updates pertaining to this vulnerability.
Vendor References
- GHSA-jwcc-j78w-j73w -
github.com/advisories/GHSA-jwcc-j78w-j73w
CVEs related to QID 981353
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jwcc-j78w-j73w | ansible |
|