QID 981585

QID 981585: Python (pip) Security Update for ansible (GHSA-3m93-m4q6-mc6v)

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to refer to GHSA-3m93-m4q6-mc6v for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981585

    Software Advisories
    Advisory ID Software Component Link
    GHSA-3m93-m4q6-mc6v ansible URL Logo github.com/advisories/GHSA-3m93-m4q6-mc6v