VDB
DEBIAN-CVE-2017-7550
DEBIAN-CVE-2017-7550
PUBLISHED
CVSS 9.800000190734863 CRITICAL
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
Risk Scores
CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | ansible | 0, 0, 0 |
| Debian:13 | ansible | 0, 0, 0 |
| Debian:14 | ansible | 0, 0, 0 |
| Debian:12 | ansible | 0, 0, 0 |
Timeline
- Nov 21, 2017 CVE Published
- Apr 28, 2026 CVE Updated