{"affected":[{"ecosystem_specific":{"binaries":[{"ansible":"2.4.6.0-3.3.1"}]},"package":{"ecosystem":"SUSE:HPE Helion OpenStack 8","name":"ansible","purl":"pkg:rpm/suse/ansible&distro=HPE%20Helion%20OpenStack%208"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.6.0-3.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ansible":"2.4.6.0-3.3.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 8","name":"ansible","purl":"pkg:rpm/suse/ansible&distro=SUSE%20OpenStack%20Cloud%208"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.6.0-3.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ansible":"2.4.6.0-3.3.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud Crowbar 8","name":"ansible","purl":"pkg:rpm/suse/ansible&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.6.0-3.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for ansible fixes the following issues:\n\nAnsible was updated to ansible 2.4.6.0.\n\nThe full release notes can be found on:\n\n\thttps://github.com/ansible/ansible/blob/stable-2.4/CHANGELOG.md\n\nSecurity issues fixed:\n\n- CVE-2018-10875: ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code. (bsc#1099808)\n- CVE-2018-10874: It was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result. (bsc#1099805)\n- CVE-2018-10855: Ansible did not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible. (bsc#1097775)\n","id":"SUSE-SU-2018:4130-1","modified":"2018-12-14T15:12:26Z","published":"2018-12-14T15:12:26Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20184130-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1097775"},{"type":"REPORT","url":"https://bugzilla.suse.com/1099805"},{"type":"REPORT","url":"https://bugzilla.suse.com/1099808"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10875"}],"related":["CVE-2018-10855","CVE-2018-10874","CVE-2018-10875"],"summary":"Security update for ansible","upstream":["CVE-2018-10855","CVE-2018-10874","CVE-2018-10875"]}