MGASA-2019-0114

Source
https://advisories.mageia.org/MGASA-2019-0114.html
Import Source
https://advisories.mageia.org/MGASA-2019-0114.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0114
Related
Published
2019-03-21T16:36:46Z
Modified
2019-03-21T16:02:37Z
Summary
Updated ansible packages fix security vulnerability
Details

The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837).

The fetch module was susceptible to path traversal (CVE-2019-3828).

References
Credits

Affected packages

Mageia:6 / ansible

Package

Name
ansible
Purl
pkg:rpm/mageia/ansible?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6.0-1.3.mga6

Ecosystem specific

{
    "section": "core"
}