MGASA-2018-0303
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 01 Jul 2018, 17:17
Last modified:16 Apr 2026, 06:25
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
01 Jul 2018, 17:17
Published
Vulnerability first disclosed
16 Apr 2026, 06:25
Last Modified
Vulnerability information updated
Description
Updated ansible packages fix security vulnerability Ansible prior to 2.4.5 does not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible (CVE-2018-10855).
Affected Systems
- mageia•ansible
< 2.4.5.0-1.1.mga5
- mageia•ansible
< 2.4.5.0-1.1.mga6