QID 995664

Date Published: 2023-10-25

QID 995664: Python (Pip) Security Update for ansible (GHSA-6fq2-x65v-v9h7)

A data disclosure flaw was found in ansible. Password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters as they are not properly wrapped. A password with special characters is exposed starting with the first of these special characters. The highest threat from this vulnerability is to data confidentiality.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Refer to Github security advisory GHSA-6fq2-x65v-v9h7 for updates and patch information.
    Vendor References

    CVEs related to QID 995664

    Software Advisories
    Advisory ID Software Component Link
    GHSA-6fq2-x65v-v9h7 ansible URL Logo github.com/advisories/GHSA-6fq2-x65v-v9h7