RSS   Vulnerabilities for 'Package hub'   RSS

2019-01-03
 
CVE-2018-16876

CWE-200
 

 
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.

 
2018-10-23
 
CVE-2018-16837

CWE-200
 

 
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

 
2018-07-13
 
CVE-2018-10875

CWE-426
 

 
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

 

 >>> Vendor: SUSE 67 Products
Suse linux
Suse linux imap server
Suse linux openexchange server
Office server
Suse email server
Suse linux admin-cd for firewall
Suse linux connectivity server
Suse linux database server
Suse linux firewall cd
Suse linux office server
Suse office server
Suse linux firewall
Suse linux firewall live-cd
Suse iptables
Suse cvsup
Suse linux school server
Suse linux standard server
Suse sled beagle
Suse open enterprise server
Linux enterprise desktop
Opensuse
Open suse
Yast2-backup
VPNC
Webyast
Studio onsite
Studio extension for system z
KIWI
Suse linux enterprise desktop
Suse linux enterprise software development kit
GCAB
Opensuse osc
Linux enterprise server
Linux enterprise debuginfo
Suse linux enterprise server
Manager
Linux enterprise software development kit
Linux enterprise workstation extension
Openstack cloud
Yast2
Manager proxy
Openstack
Linux enterprise
Suse linux enterprise live patching
Suse linux enterprise module for public cloud
Suse linux enterprise workstation extension
Linux enterprise real time extension
Opensuse leap
Suse linux enterprise real time extension
Suse linux workstation extension
Linux enterprise server for sap
Linux enterprise server for raspberry pi
Linux enterprise high availability
Linux enterprise module for web scripting
Linux enterprise for sap
Portus
Linux enterprise point of sale
Susefirewall2
Open build service
Linux enterprise module for public cloud
Subscription management tool
Shadow
Suse enterprise storage
Suse openstack cloud
Backports
Package hub
Caas platform


Copyright 2019, cxsecurity.com

 

Back to Top