[USN-4072-1] Ansible vulnerabilities
Paulo Flabiano Smorigo
pfsmorigo at canonical.com
Thu Jul 25 00:27:22 UTC 2019
Ubuntu Security Notice USN-4072-1
July 24, 2019
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 19.04
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Several security issues were fixed in Ansible.
- ansible: Configuration management, deployment, and task execution system
It was discovered that Ansible failed to properly handle sensitive information.
A local attacker could use those vulnerabilities to extract them.
It was discovered that Ansible could load configuration files from the current
working directory containing crafted commands. An attacker could run arbitrary
code as result.
It was discovered that Ansible fetch module had a path traversal vulnerability.
A local attacker could copy and overwrite files outside of the specified
The problem can be corrected by updating your system to the following
Ubuntu 18.04 LTS:
Ubuntu 16.04 LTS:
In general, a standard system update will make all the necessary changes.
CVE-2017-7481, CVE-2018-10855, CVE-2018-10874, CVE-2018-10875,
CVE-2018-16837, CVE-2018-16876, CVE-2019-10156, CVE-2019-3828
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the ubuntu-security-announce