Safety vulnerability ID: 42885
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Ansible 2.8.4 includes a fix for CVE-2019-10217: A flaw was found in Ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all GCP modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running Ansible playbooks.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10217
Latest version: 11.1.0
Radically simple IT automation
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application