ansible: Potential information disclosure via no_log directive
Published Jul 21, 2017
4.7
MEDIUMCVSS 3.0
EPSS 0.27%
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA based off of CNT 3. Further investigation determined that there was a secure method for using the directive. Notes: none.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 7
ansible
Under investigation
Red Hat OpenShift Enterprise 3
ansible
Affected
Red Hat OpenStack Platform 10 (Newton)
ansible
Will not fix
Red Hat OpenStack Platform 11 (Ocata)
ansible
Will not fix
Red Hat Storage 3
ansible
Will not fix
Red Hat Storage Console 2
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | ansible | Under investigation | n/a |
| Red Hat OpenShift Enterprise 3 | ansible | Affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | ansible | Will not fix | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
| Red Hat Storage Console 2 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Ansible Security Team and Red Hat Product Security determined that this is not a vulnerability.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Feb 14, 2025.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (4)
- https://access.redhat.com/security/cve/CVE-2017-7473 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1440912 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2017-7473
- https://www.cve.org/CVERecord?id=CVE-2017-7473
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2017-7473 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1440912 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-7473 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-7473 |
Change history (0)
No recorded changes yet.