{"id":"openSUSE-SU-2019:1125-1","summary":"Security update for ansible","details":"This update for ansible to version 2.7.8 fixes the following issues:\n\nSecurity issues fixed: \t  \n\n- CVE-2018-16837: Fixed an information leak in user module (bsc#1112959).\n- CVE-2018-16859: Fixed an issue which clould allow logging of password in plaintext in Windows powerShell (bsc#1116587).\n- CVE-2019-3828: Fixed a path traversal vulnerability in fetch module (bsc#1126503).\n- CVE-2018-10875: Fixed a potential code execution in ansible.cfg (bsc#1099808).\n- CVE-2018-16876: Fixed an issue which could allow  information disclosure in vvv+ mode with no_log on (bsc#1118896).\n\nOther issues addressed: \n\n- prepare update to 2.7.8 for multiple releases (boo#1102126, boo#1109957)\n\nRelease notes: https://github.com/ansible/ansible/blob/stable-2.7/changelogs/CHANGELOG-v2.7.rst#id1\n ","modified":"2026-03-11T07:32:04.254875Z","published":"2019-04-03T01:50:46Z","related":["CVE-2018-10875","CVE-2018-16837","CVE-2018-16859","CVE-2018-16876","CVE-2019-3828"],"upstream":["CVE-2018-10875","CVE-2018-16837","CVE-2018-16859","CVE-2018-16876","CVE-2019-3828"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/P7ES2KO7RTXEO4IZY7YGCEBV3XZND5MW/#P7ES2KO7RTXEO4IZY7YGCEBV3XZND5MW"},{"type":"REPORT","url":"https://bugzilla.suse.com/1099808"},{"type":"REPORT","url":"https://bugzilla.suse.com/1102126"},{"type":"REPORT","url":"https://bugzilla.suse.com/1109957"},{"type":"REPORT","url":"https://bugzilla.suse.com/1112959"},{"type":"REPORT","url":"https://bugzilla.suse.com/1116587"},{"type":"REPORT","url":"https://bugzilla.suse.com/1118896"},{"type":"REPORT","url":"https://bugzilla.suse.com/1126503"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10875"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16837"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16876"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-3828"}],"affected":[{"package":{"name":"ansible","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/ansible&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.8-bp150.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"ansible":"2.7.8-bp150.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1125-1.json"}},{"package":{"name":"ansible","ecosystem":"SUSE:Package Hub 15","purl":"pkg:rpm/suse/ansible&distro=SUSE%20Package%20Hub%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.8-bp150.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"ansible":"2.7.8-bp150.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1125-1.json"}},{"package":{"name":"ansible","ecosystem":"openSUSE:Leap 15.0","purl":"pkg:rpm/opensuse/ansible&distro=openSUSE%20Leap%2015.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.8-bp150.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"ansible":"2.7.8-bp150.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1125-1.json"}}],"schema_version":"1.7.5"}