RHSA-2021:0664: Moderate: Ansible security and bug fix update (2.9.18)
Ansible is a simple model-driven configuration management, multi-node<br>deployment, and remote-task execution system. Ansible works over SSH and<br>does not require any software or daemons to be installed on remote nodes.<br>Extension modules can be written in any language and are transferred to<br>managed machines automatically.<br>The following packages have been upgraded to a newer upstream version:<br>ansible (2.9.18)<br>Bug Fix(es):<br><li> CVE-2021-20178 ansible: user data leak in snmpfacts module</li> <li> CVE-2021-20180 ansible module: bitbucketpipelinevariable exposes</li> secured values<br><li> CVE-2021-20191 ansible: multiple collections exposes secured values</li> <li> CVE-2021-20228 ansible: basic.py nolog with fallback option</li> See:<br><a href="https://github.com/ansible/ansible/blob/v2.9.18/changelogs/CHANGELOG-v2.9.rst" target="blank">https://github.com/ansible/ansible/blob/v2.9.18/changelogs/CHANGELOG-v2.9.rst</a> for details on bug fixes in this release.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0664?
The severity of RHSA-2021:0664 is categorized as important.
How do I fix RHSA-2021:0664?
To fix RHSA-2021:0664, upgrade your Ansible packages to the recommended version 2.9.18-1.el8ae or 2.9.18-1.el7ae.
What affected software versions are noted in RHSA-2021:0664?
RHSA-2021:0664 affects Ansible versions up to, but not including, 2.9.18-1.el8ae and 2.9.18-1.el7ae.
What types of packages are affected by RHSA-2021:0664?
The affected packages include Ansible and Ansible-test for both el7 and el8 architectures.
Is there a specific version that resolves RHSA-2021:0664?
Yes, upgrading to Ansible version 2.9.18-1.el8ae or 2.9.18-1.el7ae resolves the issues outlined in RHSA-2021:0664.