CVE-2018-10855
03.07.2018, 01:29
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | ansible_engine | 2.4 ≤ 𝑥 < 2.4.5 |
redhat | ansible_engine | 2.5 < 𝑥 ≤ 2.5.5 |
redhat | ansible_engine | 2.0 |
redhat | cloudforms | 4.6 |
redhat | virtualization | 4.0 |
debian | debian_linux | 9.0 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 19.04 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References