CyberSec.Space Logo
返回 CVE 浏览器

CVE-2017-7550

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0330%
EPSS Percentile33.24th
Published2017年11月21日
Last Modified2026年5月13日

Vulnerability Description

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

Affected Platforms (CPE)

📦
Redhat

Ansible

>= 2.3.0 and < 2.3.3
📦
Redhat

Ansible

>= 2.4.0 and < 2.4.1
💻
Redhat

Enterprise Linux Server

= 7.0

References & Advisories

相关漏洞威胁