MGASA-2019-0234
Dashboard / Vulnerabilities / MGASA-2019-0234
Summary: Updated ansible packages fix security vulnerability
Details: Updated ansible package fixes security vulnerability: A flaw was discovered in the way Ansible templating was implemented before version 2.7.12, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed (CVE-2019-10156). Also, python-jmespath was added as a new dependency in Mageia 6.
References: https://advisories.mageia.org/MGASA-2019-0234.html, https://bugs.mageia.org/show_bug.cgi?id=25285, https://github.com/ansible/ansible/blob/stable-2.7/changelogs/CHANGELOG-v2.7.rst, https://usn.ubuntu.com/4072-1/
Affected packages
Package
Name: ansible
Purl: pkg:rpm/mageia/ansible?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
