PYSEC-2019-3

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/ansible/PYSEC-2019-3.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2019-3
Aliases
Published
2019-11-25T16:15:00Z
Modified
2023-11-01T04:49:56Z
Summary
[none]
Details

A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.

References

Affected packages

PyPI / ansible

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.8.0
Fixed
2.8.4

Affected versions

2.*
2.8.0
2.8.1
2.8.2
2.8.3

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/ansible/PYSEC-2019-3.yaml"