SUSE-SU-2021:2121-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2121-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2021:2121-1
Related
Published
2021-06-22T12:10:48Z
Modified
2021-06-22T12:10:48Z
Summary
Security update for ansible
Details

This update for ansible fixes the following issues:

  • Update to 2.9.22:
  • CVE-2021-3447: multiple modules expose secured values (bsc#1183684)
  • CVE-2021-20228: basic.py no_log with fallback option (bsc#1181935)
  • CVE-2021-20191: multiple collections exposes secured values (bsc#1181119)
  • CVE-2021-20180: bitbucketpipelinevariable exposes sensitive values (bsc#1180942)
  • CVE-2021-20178: user data leak in snmp_facts module (bsc#1180816)
References

Affected packages

SUSE:HPE Helion OpenStack 8 / ansible

Package

Name
ansible
Purl
purl:rpm/suse/ansible&distro=HPE%20Helion%20OpenStack%208

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.22-3.18.1

Ecosystem specific

{
    "binaries": [
        {
            "ansible": "2.9.22-3.18.1"
        }
    ]
}

SUSE:OpenStack Cloud 8 / ansible

Package

Name
ansible
Purl
purl:rpm/suse/ansible&distro=SUSE%20OpenStack%20Cloud%208

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.22-3.18.1

Ecosystem specific

{
    "binaries": [
        {
            "ansible": "2.9.22-3.18.1"
        }
    ]
}

SUSE:OpenStack Cloud Crowbar 8 / ansible

Package

Name
ansible
Purl
purl:rpm/suse/ansible&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.22-3.18.1

Ecosystem specific

{
    "binaries": [
        {
            "ansible": "2.9.22-3.18.1"
        }
    ]
}