Oval Definition:oval:org.opensuse.security:def:80612
Revision Date:2017-11-17Version:1
Title:Security update for ansible and monasca-installer (Moderate)
Description:

This update for ansible provides version 2.2.3.0 and fixes the following security issues:

- CVE-2017-7481: Data for lookup plugins used as variables was not being marked as 'unsafe' and could lead to unintentional disclosure of information. (bsc#1038785) - CVE-2016-9587: Prevent compromised host to execute commands on the controller (bsc#1019021). - CVE-2017-7466: Prevent arbitrary code execution on control nodes.

For more information about the upstream bugs fixed, please see /usr/share/doc/packages/ansible/CHANGELOG.md

Additionally, monasca-installer received several compatibility fixes for ansible.
Family:unixClass:patch
Status:Reference(s):1019021
1038785
1056094
CVE-2016-9587
CVE-2017-7466
CVE-2017-7481
SUSE-SU-2017:3029-1
Platform(s):SUSE OpenStack Cloud 7
Product(s):
Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • ansible-2.2.3.0-5.1 is installed
  • OR monasca-installer-20170912_10.45-5.1 is installed
  • BACK