Updated ansible packages fix security vulnerability
Publication date: 01 Jul 2018Modification date: 01 Jul 2018
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2018-10855
Description
Ansible prior to 2.4.5 does not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible (CVE-2018-10855).
References
SRPMS
5/core
- ansible-2.4.5.0-1.1.mga5
6/core
- ansible-2.4.5.0-1.1.mga6