Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2021.0420
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2021-0420)
Summary:The remote host is missing an update for the 'ansible' package(s) announced via the MGASA-2021-0420 advisory.
Description:Summary:
The remote host is missing an update for the 'ansible' package(s) announced via the MGASA-2021-0420 advisory.

Vulnerability Insight:
A flaw was found in several ansible modules, where parameters containing
credentials, such as secrets, were being logged in plain-text on managed
nodes, as well as being made visible on the controller node when run in
verbose mode.

These parameters were not protected by the no_log feature. An attacker can
take advantage of this information to steal those credentials, provided
when they have access to the log files containing them. The highest threat
from this vulnerability is to data confidentiality. This flaw affects Red
Hat Ansible Automation Platform in versions before 1.2.2 and Ansible Tower
in versions before 3.8.2 (CVE-2021-3447).

A flaw was found in Ansible, where a user's controller is vulnerable to
template injection. This issue can occur through facts used in the template
if the user is trying to put templates in multi-line YAML strings and the
facts being handled do not routinely include special template characters.
This flaw allows attackers to perform command injection, which discloses
sensitive information. The highest threat from this vulnerability is to
confidentiality and integrity (CVE-2021-3583).

Affected Software/OS:
'ansible' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
3.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-3447
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JBZ75MAMVQVZROPYHMRDQKPPVASP63DG/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MS4VPUYVLGSAKOX26IT52BSMEZRZ3KS/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RUTGO4RS4ZXZSPBU2CHVPT75IAFVTTL3/
https://bugzilla.redhat.com/show_bug.cgi?id=1939349
https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-3583
https://bugzilla.redhat.com/show_bug.cgi?id=1968412
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.