Skip to content

[GHSA-fh5v-5f35-2rv2] A flaw was found in ansible module where credentials are...#452

Merged
advisory-database[bot] merged 1 commit into
xfix/advisory-improvement-452from
xfix-GHSA-fh5v-5f35-2rv2
Jun 29, 2022
Merged

[GHSA-fh5v-5f35-2rv2] A flaw was found in ansible module where credentials are...#452
advisory-database[bot] merged 1 commit into
xfix/advisory-improvement-452from
xfix-GHSA-fh5v-5f35-2rv2

Conversation

@sugar700

Copy link
Copy Markdown

Updates

  • Affected products
  • Summary

@github-actions
github-actions Bot changed the base branch from main to xfix/advisory-improvement-452 June 27, 2022 08:03
@shelbyc

shelbyc commented Jun 27, 2022

Copy link
Copy Markdown
Contributor

Hi @xfix, thanks for bringing this vulnerability to our attention. I found the release notes for 2.8.19 and 2.9.18 that talk about CVE-2021-20180 being fixed.

I also checked to make sure the vulnerable code was not present in, for example, the 2.7 branch. The vulnerable file (bitbucket_pipeline_variable.py) does not appear until version 2.8.0a1 and I've noted this in the references.

@advisory-database
advisory-database Bot merged commit adbdd75 into xfix/advisory-improvement-452 Jun 29, 2022
@advisory-database
advisory-database Bot deleted the xfix-GHSA-fh5v-5f35-2rv2 branch June 29, 2022 12:16
@advisory-database

Copy link
Copy Markdown
Contributor

Hi @xfix! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants