First published: Thu Apr 22 2021(Updated: )
Ansible is a simple model-driven configuration management, multi-node<br>deployment, and remote-task execution system. Ansible works over SSH and<br>does not require any software or daemons to be installed on remote nodes.<br>Extension modules can be written in any language and are transferred to<br>managed machines automatically.<br>The following packages have been upgraded to a newer upstream version:<br>ansible (2.9.20)<br>Bug Fix(es):<br><li> CVE-2021-3447 ansible: multiple modules expose secured values</li> See:<br><a href="https://github.com/ansible/ansible/blob/v2.9.20/changelogs/CHANGELOG-v2.9.rst" target="_blank">https://github.com/ansible/ansible/blob/v2.9.20/changelogs/CHANGELOG-v2.9.rst</a> for details on bug fixes in this release.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible | <2.9.20-1.el8ae | 2.9.20-1.el8ae |
redhat/ansible | <2.9.20-1.el8ae | 2.9.20-1.el8ae |
redhat/ansible-test | <2.9.20-1.el8ae | 2.9.20-1.el8ae |
redhat/ansible | <2.9.20-1.el7ae | 2.9.20-1.el7ae |
redhat/ansible | <2.9.20-1.el7ae | 2.9.20-1.el7ae |
redhat/ansible-test | <2.9.20-1.el7ae | 2.9.20-1.el7ae |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:1342 is classified as moderate.
You can fix RHSA-2021:1342 by updating Ansible to version 2.9.20-1.el8ae or 2.9.20-1.el7ae.
Versions of Ansible prior to 2.9.20-1.el8ae on EL7 and EL8 are affected by RHSA-2021:1342.
Yes, RHSA-2021:1342 also affects Ansible-Test versions prior to 2.9.20-1.el8ae and 2.9.20-1.el7ae.
RHSA-2021:1342 impacts systems running Red Hat Ansible on both EL7 and EL8 platforms.