ansible: jenkins_plugin module exposes passwords in remote host logs
Published Nov 21, 2017
9.3
CRITICALCVSS 4.0
EPSS 3.56%
Description
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
Affected products
-
- Version 2.3.x before 2.3.3, 2.4.x before 2.4.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Red Hat, Inc. | Ansible | n/a |
|
No data.
Red Hat Enterprise Linux 7 Extras
ansible-0:2.4.0.0-5.el7
Fixed · RHSA-2017:2966
Red Hat OpenShift Enterprise 3
ansible
Not affected
Red Hat OpenStack Platform 10 (Newton)
ansible
Will not fix
Red Hat OpenStack Platform 11 (Ocata)
ansible
Will not fix
Red Hat OpenStack Platform 12 (Pike)
ansible
Will not fix
Red Hat Quickstart Cloud Installer 1
ansible
Under investigation
Red Hat Storage 3
ansible
Will not fix
Red Hat Storage Console 2
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extras | ansible-0:2.4.0.0-5.el7 | Fixed | RHSA-2017:2966 |
| Red Hat OpenShift Enterprise 3 | ansible | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 12 (Pike) | ansible | Will not fix | n/a |
| Red Hat Quickstart Cloud Installer 1 | ansible | Under investigation | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
| Red Hat Storage Console 2 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack Platform will no longer be updating the Ansible package in: * Red Hat OpenStack Platform 10 (Newton) * Red Hat OpenStack Platform 11 (Ocata) As of Red Hat Enterprise Linux 7.4, customers can consume an updated Ansible package directly from the extras-rhel-7.4 channel. For more information, refer to Red Hat Enterprise Linux release information.
References (9)
- https://access.redhat.com/errata/RHSA-2017:2966 vendor-advisoryx_refsource_REDHATIssue TrackingThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-7550 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1473645 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-588w-w6mv-3cw5 Advisory
- https://github.com/ansible/ansible/commit/facbf7f14da29eea67ef68ab386fc15bd06d7c7f
- https://github.com/ansible/ansible/issues/30874 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2017-4.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2017-7550
- https://www.cve.org/CVERecord?id=CVE-2017-7550
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2017:2966 | vendor-advisoryx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2017-7550 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1473645 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-588w-w6mv-3cw5 | Advisory | |
| https://github.com/ansible/ansible/commit/facbf7f14da29eea67ef68ab386fc15bd06d7c7f | ||
| https://github.com/ansible/ansible/issues/30874 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2017-4.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2017-7550 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-7550 |
Change history (0)
No recorded changes yet.