First published: Thu Oct 14 2021(Updated: )
Ansible is a simple model-driven configuration management, multi-node<br>deployment, and remote-task execution system. Ansible works over SSH and<br>does not require any software or daemons to be installed on remote nodes.<br>Extension modules can be written in any language and are transferred to<br>managed machines automatically.<br>The following packages have been upgraded to a newer upstream version:<br>ansible (2.9.27)<br>Bug Fix(es):<br><li> CVE-2021-3620 Ansible: ansible-connection module discloses sensitive info</li> in traceback error message<br>See:<br><a href="https://github.com/ansible/ansible/blob/v2.9.27/changelogs/CHANGELOG-v2.9.rst" target="_blank">https://github.com/ansible/ansible/blob/v2.9.27/changelogs/CHANGELOG-v2.9.rst</a> for details on bug fixes in this release.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible | <2.9.27-1.el8ae | 2.9.27-1.el8ae |
redhat/ansible | <2.9.27-1.el8ae | 2.9.27-1.el8ae |
redhat/ansible-test | <2.9.27-1.el8ae | 2.9.27-1.el8ae |
redhat/ansible | <2.9.27-1.el7ae | 2.9.27-1.el7ae |
redhat/ansible | <2.9.27-1.el7ae | 2.9.27-1.el7ae |
redhat/ansible-test | <2.9.27-1.el7ae | 2.9.27-1.el7ae |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:3871 is classified as important.
RHSA-2021:3871 affects Ansible and Ansible Test versions prior to 2.9.27-1.el8ae and 2.9.27-1.el7ae.
To fix RHSA-2021:3871, upgrade to Ansible version 2.9.27-1.el8ae or 2.9.27-1.el7ae.
Not addressing RHSA-2021:3871 could lead to potential security vulnerabilities within Ansible deployments.
Yes, RHSA-2021:3871 may impact system configuration management due to vulnerabilities in the affected Ansible versions.