Advisories ยป MGASA-2021-0132

Updated ansible packages fix security vulnerability

Publication date: 12 Mar 2021
Modification date: 12 Mar 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-20178 , CVE-2021-20180 , CVE-2021-20191 , CVE-2021-20228

Description

User data leak in snmp_facts module (CVE-2021-20178).

The bitbucket_pipeline_variable module exposed secured values
(CVE-2021-20180).

Multiple collections exposed secured values (CVE-2021-20191).

In basic.py, no_log with fallback option (CVE-2021-20228).

The ansible package has been updated to version 2.9.18, fixing these
issues and other bugs.
                

References

SRPMS

8/core