SB2018051521 - Red Hat update for ansible
Published: May 15, 2018 Updated: May 23, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure through log files (CVE-ID: CVE-2018-1117)
The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.
The weakness exists due to a missing no_log directive, the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclose admin passwords in the provisioning log. A local attacker can gain access to potentially sensitive information.
Remediation
Install update from vendor's website.