Back

CRITICAL

ansible: jenkins_plugin module exposes passwords in remote host logs

Published Nov 21, 2017

Description

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

Affected products

Remediation

Red Hat statement

Red Hat OpenStack Platform will no longer be updating the Ansible package in: * Red Hat OpenStack Platform 10 (Newton) * Red Hat OpenStack Platform 11 (Ocata) As of Red Hat Enterprise Linux 7.4, customers can consume an updated Ansible package directly from the extras-rhel-7.4 channel. For more information, refer to Red Hat Enterprise Linux release information.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 21, 2017
Updated Aug 5, 2024
Reserved Apr 5, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 25, 2017
GHSA-588W-W6MV-3CW5