First published: Wed Feb 24 2021(Updated: )
Ansible is a simple model-driven configuration management, multi-node<br>deployment, and remote-task execution system. Ansible works over SSH and<br>does not require any software or daemons to be installed on remote nodes.<br>Extension modules can be written in any language and are transferred to<br>managed machines automatically.<br>The following packages have been upgraded to a newer upstream version:<br>ansible (2.9.18)<br>Bug Fix(es):<br><li> CVE-2021-20178 ansible: user data leak in snmp_facts module</li> <li> CVE-2021-20180 ansible module: bitbucket_pipeline_variable exposes</li> secured values<br><li> CVE-2021-20191 ansible: multiple collections exposes secured values</li> <li> CVE-2021-20228 ansible: basic.py no_log with fallback option</li> See:<br><a href="https://github.com/ansible/ansible/blob/v2.9.18/changelogs/CHANGELOG-v2.9.rst" target="_blank">https://github.com/ansible/ansible/blob/v2.9.18/changelogs/CHANGELOG-v2.9.rst</a> for details on bug fixes in this release.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible | <2.9.18-1.el8ae | 2.9.18-1.el8ae |
redhat/ansible | <2.9.18-1.el8ae | 2.9.18-1.el8ae |
redhat/ansible-test | <2.9.18-1.el8ae | 2.9.18-1.el8ae |
redhat/ansible | <2.9.18-1.el7ae | 2.9.18-1.el7ae |
redhat/ansible | <2.9.18-1.el7ae | 2.9.18-1.el7ae |
redhat/ansible-test | <2.9.18-1.el7ae | 2.9.18-1.el7ae |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.