openSUSE Security Update : ansible (openSUSE-2020-513)

high Nessus Plugin ID 135454

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for ansible to version 2.9.6 fixes the following issues :

Security issues fixed :

- CVE-2019-14904: Fixed a vulnerability in solaris_zone module via crafted solaris zone (boo#1157968).

- CVE-2019-14905: Fixed an issue where malicious code could craft filename in nxos_file_copy module (boo#1157969).

- CVE-2019-14864: Fixed Splunk and Sumologic callback plugins leak sensitive data in logs (boo#1154830).

- CVE-2019-14846: Fixed secrets disclosure on logs due to display is hardcoded to DEBUG level (boo#1153452)

- CVE-2019-14856: Fixed insufficient fix for CVE-2019-10206 (boo#1154232)

- CVE-2019-14858: Fixed data in the sub parameter fields that will not be masked and will be displayed when run with increased verbosity (boo#1154231)

- CVE-2019-10206: ansible-playbook -k and ansible cli tools prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them. (boo#1142690)

- CVE-2019-10217: Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly.
service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks. (boo#1144453)

Solution

Update the affected ansible packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1137479

https://bugzilla.opensuse.org/show_bug.cgi?id=1142542

https://bugzilla.opensuse.org/show_bug.cgi?id=1142690

https://bugzilla.opensuse.org/show_bug.cgi?id=1144453

https://bugzilla.opensuse.org/show_bug.cgi?id=1153452

https://bugzilla.opensuse.org/show_bug.cgi?id=1154231

https://bugzilla.opensuse.org/show_bug.cgi?id=1154232

https://bugzilla.opensuse.org/show_bug.cgi?id=1154830

https://bugzilla.opensuse.org/show_bug.cgi?id=1157968

https://bugzilla.opensuse.org/show_bug.cgi?id=1157969

Plugin Details

Severity: High

ID: 135454

File Name: openSUSE-2020-513.nasl

Version: 1.5

Type: local

Agent: unix

Published: 4/14/2020

Updated: 3/19/2024

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.6

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.8

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:P/A:P

CVSS Score Source: CVE-2019-14904

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2019-14846

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:ansible, p-cpe:/a:novell:opensuse:ansible-test, cpe:/o:novell:opensuse:15.1

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/12/2020

Vulnerability Publication Date: 10/8/2019

Reference Information

CVE: CVE-2019-10206, CVE-2019-10217, CVE-2019-14846, CVE-2019-14856, CVE-2019-14858, CVE-2019-14864, CVE-2019-14904, CVE-2019-14905