MGASA-2018-0303

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 01 Jul 2018, 17:17
Last modified:16 Apr 2026, 06:25

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Jul 2018, 17:17
Published
Vulnerability first disclosed
16 Apr 2026, 06:25
Last Modified
Vulnerability information updated

Description

Updated ansible packages fix security vulnerability Ansible prior to 2.4.5 does not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible (CVE-2018-10855).

Affected Systems

  • mageiaansible

    < 2.4.5.0-1.1.mga5

  • mageiaansible

    < 2.4.5.0-1.1.mga6

References (4)