CVE-2017-7550
published 2017-11-21CVE-2017-7550: A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.53%
87.9th percentile
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.4.2.0+dfsg-1 (bookworm) | ansible 2.4.2.0+dfsg-1 (bookworm) |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.41 | 2.0.0+dfsg-2ubuntu1.41 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.28 | 1:2.5+dfsg-5ubuntu10.28 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.1 | 1:2.11+dfsg-1ubuntu7.1 |
| red_hat_inc | ansible | — | — |
| redhat | ansible | >= 0 < 2.4.2.0+dfsg-1 | 2.4.2.0+dfsg-1 |
| redhat | ansible | >= 0 < 2.4.2.0+dfsg-1 | 2.4.2.0+dfsg-1 |
| redhat | ansible | >= 0 < 2.4.2.0+dfsg-1 | 2.4.2.0+dfsg-1 |
| redhat | ansible | >= 0 < 2.4.2.0+dfsg-1 | 2.4.2.0+dfsg-1 |
| redhat | ansible | >= 2.3.0 < 2.3.3 | 2.3.3 |
| redhat | ansible | >= 2.3.0.0 < 2.3.3.0 | 2.3.3.0 |
| redhat | ansible | >= 2.4.0 < 2.4.1 | 2.4.1 |
| redhat | ansible | >= 2.4.0.0 < 2.4.1.0 | 2.4.1.0 |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv10.0CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Ansible Insertion of Sensitive Information into Log File vulnerability
osv·2022-05-13
CVE-2017-7550 [CRITICAL] Ansible Insertion of Sensitive Information into Log File vulnerability
Ansible Insertion of Sensitive Information into Log File vulnerability
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
GHSA
Ansible Insertion of Sensitive Information into Log File vulnerability
ghsa·2022-05-13
CVE-2017-7550 [CRITICAL] CWE-532 Ansible Insertion of Sensitive Information into Log File vulnerability
Ansible Insertion of Sensitive Information into Log File vulnerability
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
OSV
qemu vulnerabilities
osv·2018-05-16·CVSS 10.0
CVE-2017-16845 qemu vulnerabilities
qemu vulnerabilities
Cyrille Chatras discovered that QEMU incorrectly handled certain PS2 values
during migration. An attacker could possibly use this issue to cause QEMU
to crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 18.04 LTS. (CVE-2017-16845)
Cyrille Chatras discovered that QEMU incorrectly handled multiboot. An
attacker could use this issue to cause QEMU to crash, resulting in a denial
of service, or possibly execute arbitrary code on the host. In the default
installation, when QEMU is used with libvirt, attackers would be isolated
by the libvirt AppArmor profile. (CVE-2018-7550)
Ross Lagerwall discovered that QEMU incorrectly handled the Cirrus VGA
device. A privileged attacker inside the guest could use this issue to
OSV
CVE-2017-7550: A flaw was found in the way Ansible (2
osv·2017-11-21·CVSS 9.8
CVE-2017-7550 [CRITICAL] CVE-2017-7550: A flaw was found in the way Ansible (2
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
Red Hat
ansible: jenkins_plugin module exposes passwords in remote host logs
vendor_redhat·2017-09-25·CVSS 9.8
CVE-2017-7550 [CRITICAL] CWE-532 ansible: jenkins_plugin module exposes passwords in remote host logs
ansible: jenkins_plugin module exposes passwords in remote host logs
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
A flaw was found in the way Ansible passed certain parameters to the jenkins_plugin module. A remote attacker could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
Statement: Red Hat OpenStack Platform wi
Debian
CVE-2017-7550: ansible - A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1)...
vendor_debian·2017·CVSS 9.8
CVE-2017-7550 [CRITICAL] CVE-2017-7550: ansible - A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1)...
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.
Scope: local
bookworm: resolved (fixed in 2.4.2.0+dfsg-1)
bullseye: resolved (fixed in 2.4.2.0+dfsg-1)
forky: resolved (fixed in 2.4.2.0+dfsg-1)
sid: resolved (fixed in 2.4.2.0+dfsg-1)
trixie: resolved (fixed in 2.4.2.0+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7550 ansible: jenkins_plugin module exposes passwords in remote host logs [epel-all]
bugzilla·2017-09-25·CVSS 9.8
CVE-2017-7550 [CRITICAL] CVE-2017-7550 ansible: jenkins_plugin module exposes passwords in remote host logs [epel-all]
CVE-2017-7550 ansible: jenkins_plugin module exposes passwords in remote host logs [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2017-7550 ansible: jenkins_plugin module exposes passwords in remote host logs [fedora-all]
bugzilla·2017-09-25·CVSS 9.8
CVE-2017-7550 [CRITICAL] CVE-2017-7550 ansible: jenkins_plugin module exposes passwords in remote host logs [fedora-all]
CVE-2017-7550 ansible: jenkins_plugin module exposes passwords in remote host logs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2017-7550 ansible: jenkins_plugin module exposes passwords in remote host logs
bugzilla·2017-07-21·CVSS 9.8
CVE-2017-7550 [CRITICAL] CVE-2017-7550 ansible: jenkins_plugin module exposes passwords in remote host logs
CVE-2017-7550 ansible: jenkins_plugin module exposes passwords in remote host logs
It was discovered that jenkins_plugin module in Ansible exposes passwords with the params attribute in the system logs of the remote host. Low privileged user on remote host can access the logs and is able to log into Jenkins instance as administrator.
Discussion:
Acknowledgments:
Name: Stefano Mazzucco (Kirontech)
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1495237]
Affects: fedora-all [bug 1495236]
---
I took a look at this bug upstream and filed: https://github.com/ansible/ansible/issues/30874
It looks to be mostly a documentation bug. The jenkins_plugin is a community written plugin. It logs into a jenkins server to manage plugins installed there. The plugin has the
2017-11-21
Published