QID 982362

QID 982362: Python (pip) Security Update for ansible (GHSA-wv5p-gmmv-wh9v)

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Customers are advised to refer to GHSA-wv5p-gmmv-wh9v for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982362

    Software Advisories
    Advisory ID Software Component Link
    GHSA-wv5p-gmmv-wh9v ansible URL Logo github.com/advisories/GHSA-wv5p-gmmv-wh9v