Skip to content

Comments

[GHSA-2pfh-q76x-gwvm] Improper Input Validation and Command Injection in Ansible#181

Closed
stschmitt wants to merge 1 commit intostschmitt/advisory-improvement-181from
stschmitt-GHSA-2pfh-q76x-gwvm
Closed

[GHSA-2pfh-q76x-gwvm] Improper Input Validation and Command Injection in Ansible#181
stschmitt wants to merge 1 commit intostschmitt/advisory-improvement-181from
stschmitt-GHSA-2pfh-q76x-gwvm

Conversation

@stschmitt
Copy link

Updates

  • Affected products
  • References

@github-actions github-actions bot changed the base branch from main to stschmitt/advisory-improvement-181 April 6, 2022 09:47
@darakian
Copy link
Contributor

darakian commented Apr 6, 2022

Hey there. Thanks for the contribution, but where are you seeing 3.4.0 as a fixed version? Digging in to the release notes it looks like 3.4.0 uses ansible base version 2.10.9
https://github.com/ansible-community/ansible-build-data/blob/main/3/CHANGELOG-v3.rst

The PR you reference is tagged for versions from v2.12.0b1

@jhampson-dbre
Copy link

ansible 4.2 contains ansible-core 2.11.2 which contains the fix for CVE-2021-3583. I think the ansible CVEs are confusing since they split the ansible package into ansible and ansible-base (2.10) and then ansible-core (2.11).

However, CVE-2021-3583 is fixed in ansible 2.9.23 where there was just the single package. fixed": "2.9.23 , 4.2.0" might be more accurate here.
https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst#v2923

@darakian
Copy link
Contributor

Indeed they are confusing and yes 2.9.23 might make more sense as a fix version. @stschmitt, do you have any reference for 3.4.0 or does @jhampson-dbre's suggestion make more sense to you?

@advisory-database advisory-database bot closed this Jun 1, 2022
@github-actions github-actions bot deleted the stschmitt-GHSA-2pfh-q76x-gwvm branch June 1, 2022 22:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants