CyberSec.Space Logo
Back to CVE Browser

CVE-2017-7550

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0330%
EPSS Percentile33.24th
PublishedNov 21, 2017
Last ModifiedMay 13, 2026

Vulnerability Description

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

Affected Platforms (CPE)

πŸ“¦
Redhat

Ansible

>= 2.3.0 and < 2.3.3
πŸ“¦
Redhat

Ansible

>= 2.4.0 and < 2.4.1
πŸ’»
Redhat

Enterprise Linux Server

= 7.0

References & Advisories

Related Vulnerabilities