QID 981357

QID 981357: Python (pip) Security Update for ansible (GHSA-923p-fr2c-g5m2)

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 3.9 severity.
  • CVSS V2 rated as Medium - 3.3 severity.
  • Solution
    Customers are advised to refer to GHSA-923p-fr2c-g5m2 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981357

    Software Advisories
    Advisory ID Software Component Link
    GHSA-923p-fr2c-g5m2 ansible URL Logo github.com/advisories/GHSA-923p-fr2c-g5m2