RHSA-2021:1342: Moderate: Ansible security update (2.9.20)
Ansible is a simple model-driven configuration management, multi-nodedeployment, and remote-task execution system. Ansible works over SSH anddoes not require any software or daemons to be installed on remote nodes.Extension modules can be written in any language and are transferred tomanaged machines automatically.The following packages have been upgraded to a newer upstream version:ansible (2.9.20)Bug Fix(es): CVE-2021-3447 ansible: multiple modules expose secured values See:https://github.com/ansible/ansible/blob/v2.9.20/changelogs/CHANGELOG-v2.9.rst for details on bug fixes in this release.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ansibleto a version that resolves this vulnerability.Fixed in 2.9.20-1.el8ae - Upgrade
Upgrade
redhat/ansible-testto a version that resolves this vulnerability.Fixed in 2.9.20-1.el8ae - Upgrade
Upgrade
redhat/ansibleto a version that resolves this vulnerability.Fixed in 2.9.20-1.el7ae - Upgrade
Upgrade
redhat/ansible-testto a version that resolves this vulnerability.Fixed in 2.9.20-1.el7ae - Upgrade
Upgrade
ansible/ansibleto a version that resolves this vulnerability.Fixed in 2.9.20
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:1342?
The severity of RHSA-2021:1342 is classified as moderate.
How do I fix RHSA-2021:1342?
You can fix RHSA-2021:1342 by updating Ansible to version 2.9.20-1.el8ae or 2.9.20-1.el7ae.
Which versions of Ansible are affected by RHSA-2021:1342?
Versions of Ansible prior to 2.9.20-1.el8ae on EL7 and EL8 are affected by RHSA-2021:1342.
Does RHSA-2021:1342 affect Ansible-Test?
Yes, RHSA-2021:1342 also affects Ansible-Test versions prior to 2.9.20-1.el8ae and 2.9.20-1.el7ae.
What type of systems are impacted by RHSA-2021:1342?
RHSA-2021:1342 impacts systems running Red Hat Ansible on both EL7 and EL8 platforms.