First published: Thu Oct 14 2021(Updated: )
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language.<br>Security Fix(es):<br><li> ansible: ansible-connection module discloses sensitive info in traceback error message </li> (CVE-2021-3620)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s)<br>listed in the References section.<br>Additional Changes:<br>This update fixes various bugs and adds enhancements.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible | <2.9.27-1.el8a | 2.9.27-1.el8a |
redhat/ansible-core | <2.11.6-1.el8a | 2.11.6-1.el8a |
redhat/ansible-test | <2.11.6-1.el8a | 2.11.6-1.el8a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:3874 is classified as important.
To fix RHSA-2021:3874, update Ansible to version 2.9.27-1.el8a or Ansible Core to version 2.11.6-1.el8a.
RHSA-2021:3874 affects Ansible, Ansible Core, and Ansible Test packages.
Yes, upgrade to Ansible 2.9.27-1.el8a or Ansible Core 2.11.6-1.el8a to remediate RHSA-2021:3874.
Addressing RHSA-2021:3874 is crucial to mitigate potential vulnerabilities that could exploit the affected software components.