Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Ansible to 2.6.14 #4345

Closed
emkll opened this issue Apr 15, 2019 · 0 comments · Fixed by #4346
Closed

Update Ansible to 2.6.14 #4345

emkll opened this issue Apr 15, 2019 · 0 comments · Fixed by #4346
Labels
Milestone

Comments

@emkll
Copy link
Contributor

emkll commented Apr 15, 2019

From Github Dependency Graph notification:

Any version prior to 2.6.14 is vulnerable to CVE-2019-3828:

[...] path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

All servers the Admin workstation should be connected to are trusted, and Admin workstations should not contain information other than what's running on the servers. To ensure defense-in-depth and resolve alerting noise, we should update this dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants