A security flaw was found in Ansible Engine, all Ansible 2.7.x versions before 2.7.17, all Ansible 2.8.x versions before 2.8.11 and all Ansible 2.9.x versions before 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command line, not using an environment variable or an input configuration file. This will disclose passwords and tokens from process list and no_log directive from debug module would not have any effect making these secrets being disclosed on stdout and log files.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
redhat ansible tower |
||
redhat ansible engine |
||
debian debian linux 10.0 |
||
fedoraproject fedora 30 |
||
fedoraproject fedora 31 |
||
fedoraproject fedora 32 |