• 公告ID (KylinSec-SA-2021-1683)

摘要:

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

安全等级: Low

公告ID: KylinSec-SA-2021-1683

发布日期: 2021年9月23日

关联CVE: CVE-2019-14864  

  • 详细介绍

1. 漏洞描述

   

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2019-14864 KY3.4-4A ansible Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2021-1682 下一篇:KylinSec-SA-2021-1347