ansible-core-2.16.3-2.el8.ML.1

エラータID: AXSA:2024-8343:02

Release date: 
Tuesday, June 18, 2024 - 16:12
Subject: 
ansible-core-2.16.3-2.el8.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.

Security Fix(es):

* ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration (CVE-2024-0690)

Bug Fix(es):

* Update ansible-core to 2.16.3 (JIRA:RHEL-23782)
* Rebuild ansible-core with python 3.12 (JIRA:RHEL-24141)

CVE-2024-0690
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ansible-core-2.16.3-2.el8.ML.1.src.rpm
    MD5: 8f8b800e27f99af08f8704f0fc037ddd
    SHA-256: 8d8457abcb620a2c5e8f2ef59fd409d3f630dae2f84b3e320f1879cbdf807d18
    Size: 8.30 MB

Asianux Server 8 for x86_64
  1. ansible-core-2.16.3-2.el8.ML.1.x86_64.rpm
    MD5: c61a0eb0fa01d631755d03a9a029fb04
    SHA-256: 56411a333c6c3e2167712fc4d378e392e203677bd4ed4735be7a3fd40a677868
    Size: 3.64 MB
  2. ansible-test-2.16.3-2.el8.ML.1.x86_64.rpm
    MD5: 44902b0e526e2c28365903e1c847886b
    SHA-256: eb0e6424b697b8f7cd9534b60d7780b96de795045c17905a1fd1fbba1af8954a
    Size: 944.88 kB