FlawAtlas
Search the atlas
SUSE-SU-2021:4152-1 Not scored

Security update for ansible

This update for ansible fixes the following issues: Update to 2.9.27: - CVE-2021-3620: ansible-connection module discloses sensitive info in traceback error message (bsc#1187725). - CVE-2021-3583: Template Injection through yaml multi-line strings with ansible facts used in template (bsc#1188061). - ansible module nmcli is broken in ansible 2.9.13 (bsc#1176460)

Exploit probability Not scored
Published December 22, 2021
Required by Not available
Last source change May 2, 2025

02 / AFFECTED SOFTWARE

Affected packages

SUSE:HPE Helion OpenStack 8 ansible
SUSE:OpenStack Cloud 8 ansible
SUSE:OpenStack Cloud Crowbar 8 ansible

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2021:4152-1

This update for ansible fixes the following issues: Update to 2.9.27: - CVE-2021-3620: ansible-connection module discloses sensitive info in traceback error message (bsc#1187725). - CVE-2021-3583: Template Injection through yaml multi-line strings with ansible facts used in template (bsc#1188061). - ansible module nmcli is broken in ansible 2.9.13 (bsc#1176460)

View original source

05 / REFERENCES

Further evidence