RHSA-2020:1544: Important: Ansible security and bug fix update (2.7.17)
Ansible is a simple model-driven configuration management, multi-node<br>deployment, and remote-task execution system. Ansible works over SSH and<br>does not require any software or daemons to be installed on remote nodes.<br>Extension modules can be written in any language and are transferred to<br>managed machines automatically.<br>The following packages have been upgraded to a newer upstream version:<br>ansible (2.7.17)<br>Bug Fix(es):<br><li> CVE-2020-10684 Ansible: code injection when using ansiblefacts as a</li> subkey<br><li> CVE-2020-10685 Ansible: modules which use files encrypted with vault are</li> not properly cleaned up<br><li> CVE-2020-1733 ansible: insecure temporary directory when running</li> becomeuser from become directive<br><li> CVE-2020-1735 ansible: path injection on dest parameter in fetch module</li> <li> CVE-2020-1737 ansible: Extract-Zip function in winunzip module does not</li> check extracted path<br><li> CVE-2020-1739 ansible: svn module leaks password when specified as a</li> parameter<br><li> CVE-2020-1740 ansible: secrets readable after ansible-vault edit</li> <li> CVE-2020-1746 ansible: Information disclosure issue in ldapattr and</li> ldapentry modules<br>See:<br><a href="https://github.com/ansible/ansible/blob/v2.7.17/changelogs/CHANGELOG-v2.7.rst" target="blank">https://github.com/ansible/ansible/blob/v2.7.17/changelogs/CHANGELOG-v2.7.rst</a> for details on bug fixes in this release.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1544?
The severity of RHSA-2020:1544 is classified as moderate.
How do I fix RHSA-2020:1544?
You can fix RHSA-2020:1544 by updating the Ansible package to version 2.7.17-1.el7ae.
What software is affected by RHSA-2020:1544?
The affected software for RHSA-2020:1544 is the Ansible package versions prior to 2.7.17-1.el7ae.
What are the risks of not addressing RHSA-2020:1544?
Not addressing RHSA-2020:1544 may expose systems to potential security vulnerabilities.
Is RHSA-2020:1544 applicable to all Red Hat systems?
RHSA-2020:1544 is specifically applicable to Red Hat Enterprise Linux systems running affected versions of Ansible.