ansible-core-2.14.14-1.el9.ML.1

エラータID: AXSA:2024-8083:01

Release date: 
Friday, May 31, 2024 - 20:06
Subject: 
ansible-core-2.14.14-1.el9.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.

Security Fix(es):

* ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration (CVE-2024-0690)

Bug Fix(es):

* Update ansible-core to 2.14.14 (JIRA:RHEL-23783)

CVE-2024-0690
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ansible-core-2.14.14-1.el9.ML.1.src.rpm
    MD5: 49e2addf8894c7306cca4343d191e0d1
    SHA-256: 5b2ba2f14de7ca1ff617c7ec56591a00e5abc7f861aaa39c0adc098fd0497e89
    Size: 11.28 MB

Asianux Server 9 for x86_64
  1. ansible-core-2.14.14-1.el9.ML.1.x86_64.rpm
    MD5: a7a53334dbf6110aba53f8691ebef480
    SHA-256: 96a3f9b139aed53451c1b2e6964a1a07cade735e43420e9eca16c1d6f8844f3f
    Size: 2.20 MB
  2. ansible-test-2.14.14-1.el9.ML.1.x86_64.rpm
    MD5: c8ed39d3ea0d9574f64340ab042a7bb8
    SHA-256: 010488a37793810c616aa1105489cf7d5fe0080fb3e513c420b793b9d6d76b87
    Size: 684.44 kB