—
PYSEC-2022-164
상세
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
PyPI / ansible
최초 영향 버전:
0 수정 버전: fe28767970c8ec62aabe493c46b53a5de1e5fac0 수정
pip install --upgrade 'ansible>=fe28767970c8ec62aabe493c46b53a5de1e5fac0' 참고
- https://github.com/ansible/ansible/commit/fe28767970c8ec62aabe493c46b53a5de1e5fac0 [FIX]
- https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst#security-fixes [WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1975767 [REPORT]
- https://github.com/advisories/GHSA-4r65-35qq-ch8j [ADVISORY]