QID 981585
QID 981585: Python (pip) Security Update for ansible (GHSA-3m93-m4q6-mc6v)
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3m93-m4q6-mc6v for updates pertaining to this vulnerability.
Vendor References
- GHSA-3m93-m4q6-mc6v -
github.com/advisories/GHSA-3m93-m4q6-mc6v
CVEs related to QID 981585
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3m93-m4q6-mc6v | ansible |
|