CVE-2017-7550
21.11.2017, 17:29
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | ansible | 2.3.0 ≤ 𝑥 < 2.3.3 |
redhat | ansible | 2.4.0 ≤ 𝑥 < 2.4.1 |
redhat | enterprise_linux_server | 7.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References