Update dependency ansible to v12 [SECURITY]#124
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
Conversation
Author
Branch automerge failureThis PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.
|
bff758c to
34fbcf8
Compare
2184afe to
938e9dc
Compare
938e9dc to
eb2380a
Compare
eb2380a to
23e3f56
Compare
23e3f56 to
81a400b
Compare
81a400b to
88e6d78
Compare
88e6d78 to
aa43826
Compare
aa43826 to
baefbb7
Compare
baefbb7 to
25a3229
Compare
25a3229 to
4949da5
Compare
4949da5 to
48070d0
Compare
48070d0 to
1a37118
Compare
ee92adb to
aec920c
Compare
c265ebb to
c906676
Compare
c906676 to
0058950
Compare
0058950 to
b9f24f9
Compare
b9f24f9 to
16d1d24
Compare
16d1d24 to
fe61d57
Compare
fe61d57 to
931c17b
Compare
931c17b to
5fa2cc7
Compare
5fa2cc7 to
15739ab
Compare
15739ab to
fcd26ba
Compare
fcd26ba to
1a29fef
Compare
1a29fef to
4980b96
Compare
Author
|
4980b96 to
2d3a7f2
Compare
2d3a7f2 to
32fabeb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==5.4.0→==12.2.0Ansible leaks password to logs
CVE-2022-3697 / GHSA-cpx3-93w7-457x
More information
Details
A flaw was found in Ansible in the amazon.aws collection when using the
tower_callbackparameter from theamazon.aws.ec2_instancemodule. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Ansible symlink attack vulnerability
CVE-2023-5115 / GHSA-jpvw-p8pr-9g2x
More information
Details
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Ansible Community General Collection is vulnerable to exposure of sensitive information
CVE-2025-14010 / GHSA-8ggh-xwr9-3373
More information
Details
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attackers with access to logs could retrieve these secrets and potentially compromise Keycloak accounts or administrative access.
Severity
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
ansible-community/ansible-build-data (ansible)
v12.2.0Compare Source
v12.1.0Compare Source
v12.0.0Compare Source
v11.13.0Compare Source
v11.12.0Compare Source
v11.11.0Compare Source
v11.10.0Compare Source
v11.9.0Compare Source
v11.8.0Compare Source
v11.7.0Compare Source
v11.6.0Compare Source
v11.5.0Compare Source
v11.4.0Compare Source
v11.3.0Compare Source
v11.2.0Compare Source
v11.1.0Compare Source
v11.0.0Compare Source
v10.7.0Compare Source
v10.6.0Compare Source
v10.5.0Compare Source
v10.4.0Compare Source
v10.3.0Compare Source
v10.2.0Compare Source
v10.1.0Compare Source
v10.0.1Compare Source
v9.13.0Compare Source
v9.12.0Compare Source
v9.11.0Compare Source
v9.10.0Compare Source
v9.9.0Compare Source
v9.8.0Compare Source
v9.7.0Compare Source
v9.6.1Compare Source
v9.5.1Compare Source
v9.4.0Compare Source
v9.3.0Compare Source
v9.2.0Compare Source
v9.1.0Compare Source
v9.0.1Compare Source
v8.7.0Compare Source
v8.6.1Compare Source
v8.6.0Compare Source
v8.3.0Compare Source
v8.2.0Compare Source
v8.1.0Compare Source
v8.0.0Compare Source
v7.7.0Compare Source
v7.6.0Compare Source
v7.5.0Compare Source
v7.4.0Compare Source
v7.1.0Compare Source
v7.0.0Compare Source
v6.7.0Compare Source
v6.6.0Compare Source
v6.5.0Compare Source
v6.4.0Compare Source
v6.3.0Compare Source
v6.2.0Compare Source
v6.1.0Compare Source
v5.9.0Compare Source
v5.8.0Compare Source
v5.7.1Compare Source
v5.7.0Compare Source
v5.6.0Compare Source
v5.5.0Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.