Updated ansible package fixes security vulnerability
Publication date: 02 Nov 2017Modification date: 02 Nov 2017
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-7550
Description
A flaw was found in the way Ansible passed certain parameters to the jenkins_plugin module. A remote attacker could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation (CVE-2017-7550). The ansible package has been updated to version 2.4.1 to fix this issue and several other bugs.
References
SRPMS
6/core
- ansible-2.4.1.0-1.1.mga6
5/core
- ansible-2.4.1.0-1.1.mga5