Advisories ยป MGASA-2018-0303

Updated ansible packages fix security vulnerability

Publication date: 01 Jul 2018
Modification date: 01 Jul 2018
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2018-10855

Description

Ansible prior to 2.4.5 does not honor the no_log task flag for failed
tasks.  When the no_log flag has been used to protect sensitive data
passed to a task from being logged, and that task does not run
successfully, Ansible will expose sensitive data in log files and on the
terminal of the user running Ansible (CVE-2018-10855).
                

References

SRPMS

6/core

5/core