Overview

Request 537596 accepted

CVE-2017-7481: Security issue with lookup return not tainting the jinja2 environment (bsc#1038785)
CVE-2016-9587: host to controller command execution vulnerability (bsc#1019021)
CVE-2016-8628: Command injection by compromised server via fact variables (bsc#1008037)
CVE-2016-8614: Improper verification of key fingerprints in apt_key module (bsc#1008038)


Michael Ströder's avatar

Although this is an upstream release update I strongly support it because given the fast pace of ansible releases with important security and functional fixes it's a very bad idea to fall behind.

Back-porting security fixes would be a pain and nobody seriously using on ansible would want to use such a patched ansible package anyway.


Andreas Stieger's avatar

Please accept the review on this case


Andreas Stieger's avatar

This also fixes CVE-2017-7550, not mentioned in the changelog


Michael Ströder's avatar

This is an upstream update anyway.

So being an ansible user mayself I strongly recommend to rather use upstream release 2.4.1.0 which fixes some issues found in 2.4.0.0.


Andreas Stieger's avatar

Would you then either approve, reject, supersede or submit updates to the stable distributions pro-actively?


Michael Ströder's avatar

I'm not the one who decides on this.

But I'd support it because given the fast pace of ansible releases with important security and functional fixes it's a very bad idea to fall behind. Back-porting security fixes would be a pain and nobody relying on ansible would want to use such a patched ansible package anyway.


Andreas Stieger's avatar

Actually you are? You are the maintainer.

Request History
Andreas Stieger's avatar

AndreasStieger created request

CVE-2017-7481: Security issue with lookup return not tainting the jinja2 environment (bsc#1038785)
CVE-2016-9587: host to controller command execution vulnerability (bsc#1019021)
CVE-2016-8628: Command injection by compromised server via fact variables (bsc#1008037)
CVE-2016-8614: Improper verification of key fingerprints in apt_key module (bsc#1008038)


Maintenance Bot's avatar

maintbot added factory-source as a reviewer


Maintenance Bot's avatar

maintbot added as a reviewer

Submission for ansible by someone who is not maintainer in the devel project (systemsmanagement). Please review


Maintenance Bot's avatar

maintbot accepted review

ok


Source in Factory Checker's avatar

factory-source added backports-reviewers as a reviewer

Automated review failed. Needs fallback reviewer.


Source in Factory Checker's avatar

factory-source accepted review

the package needs to be accepted in openSUSE:Factory or openSUSE:Leap:42.2:Update or openSUSE:Leap:42.2 or openSUSE:Leap:42.1:Update or openSUSE:Leap:42.1 first


Michael Ströder's avatar

stroeder accepted review


Andreas Stieger's avatar

AndreasStieger accepted request

start update, again bypassing backports-reviewers

openSUSE Build Service is sponsored by