Advisories ยป MGASA-2017-0399

Updated ansible package fixes security vulnerability

Publication date: 02 Nov 2017
Modification date: 02 Nov 2017
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-7550

Description

A flaw was found in the way Ansible passed certain parameters to the
jenkins_plugin module. A remote attacker could use this flaw to expose
sensitive information from a remote host's logs. This flaw was fixed by
not allowing passwords to be specified in the "params" argument, and
noting this in the module documentation (CVE-2017-7550).

The ansible package has been updated to version 2.4.1 to fix this issue
and several other bugs.
                

References

SRPMS

6/core

5/core