Hide Forgot
ansible-playbook -k and ansible cli tools prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
Acknowledgments: Name: Paul Rubin
Fix got merged into development https://github.com/ansible/ansible/pull/59246 backports: 2.8.x https://github.com/ansible/ansible/pull/59552 2.7.x https://github.com/ansible/ansible/pull/59553 2.6.x https://github.com/ansible/ansible/pull/59554
This issue has been addressed in the following products: Red Hat Ansible Engine 2.7 for RHEL 7 Via RHSA-2019:2544 https://access.redhat.com/errata/RHSA-2019:2544
This issue has been addressed in the following products: Red Hat Ansible Engine 2.6 for RHEL 7 Via RHSA-2019:2545 https://access.redhat.com/errata/RHSA-2019:2545
This issue has been addressed in the following products: Red Hat Ansible Engine 2 for RHEL 7 Red Hat Ansible Engine 2 for RHEL 8 Via RHSA-2019:2543 https://access.redhat.com/errata/RHSA-2019:2543
This issue has been addressed in the following products: Red Hat Ansible Engine 2.8 for RHEL 7 Red Hat Ansible Engine 2.8 for RHEL 8 Via RHSA-2019:2542 https://access.redhat.com/errata/RHSA-2019:2542
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-10206
Gluster uses Ansible package from Ansible repository and hence it will consume fixes from core Ansible. For Ceph-3 we still maintain Ansible atleast for Ubuntu, Ceph-2 has reached end of life and hence out of support scope.
The vulnerable code was included in all versions shipped with OpenStack 10, 13 and 14.
This issue has been addressed in the following products: Red Hat OpenStack Platform 14.0 (Rocky) Via RHSA-2019:3744 https://access.redhat.com/errata/RHSA-2019:3744
This issue has been addressed in the following products: Red Hat OpenStack Platform 13.0 (Queens) Via RHSA-2019:3789 https://access.redhat.com/errata/RHSA-2019:3789
External References: https://github.com/ansible/ansible/pull/59246