VDB

DEBIAN-CVE-2017-7550

DEBIAN-CVE-2017-7550 PUBLISHED CVSS 9.800000190734863 CRITICAL

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11ansible0, 0, 0
Debian:13ansible0, 0, 0
Debian:14ansible0, 0, 0
Debian:12ansible0, 0, 0

Timeline

  • Nov 21, 2017 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›