Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2021.0420
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2021-0420)
Zusammenfassung:The remote host is missing an update for the 'ansible' package(s) announced via the MGASA-2021-0420 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'ansible' package(s) announced via the MGASA-2021-0420 advisory.

Vulnerability Insight:
A flaw was found in several ansible modules, where parameters containing
credentials, such as secrets, were being logged in plain-text on managed
nodes, as well as being made visible on the controller node when run in
verbose mode.

These parameters were not protected by the no_log feature. An attacker can
take advantage of this information to steal those credentials, provided
when they have access to the log files containing them. The highest threat
from this vulnerability is to data confidentiality. This flaw affects Red
Hat Ansible Automation Platform in versions before 1.2.2 and Ansible Tower
in versions before 3.8.2 (CVE-2021-3447).

A flaw was found in Ansible, where a user's controller is vulnerable to
template injection. This issue can occur through facts used in the template
if the user is trying to put templates in multi-line YAML strings and the
facts being handled do not routinely include special template characters.
This flaw allows attackers to perform command injection, which discloses
sensitive information. The highest threat from this vulnerability is to
confidentiality and integrity (CVE-2021-3583).

Affected Software/OS:
'ansible' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
3.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2021-3447
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JBZ75MAMVQVZROPYHMRDQKPPVASP63DG/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MS4VPUYVLGSAKOX26IT52BSMEZRZ3KS/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RUTGO4RS4ZXZSPBU2CHVPT75IAFVTTL3/
https://bugzilla.redhat.com/show_bug.cgi?id=1939349
https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-3583
https://bugzilla.redhat.com/show_bug.cgi?id=1968412
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.