QID 982361

QID 982361: Python (pip) Security Update for ansible (GHSA-8f4m-hccc-8qph)

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Customers are advised to refer to GHSA-8f4m-hccc-8qph for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982361

    Software Advisories
    Advisory ID Software Component Link
    GHSA-8f4m-hccc-8qph ansible URL Logo github.com/advisories/GHSA-8f4m-hccc-8qph