FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

nothing found there

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
67dbeeb6-80f4-11ea-bafd-815569f3852dansible - subversion password leak from PID

Borja Tarraso reports:

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.


Discovery 2020-02-12
Entry 2020-04-17
ansible
lt 2.8.9

ansible27
lt 2.7.17

ansible26
lt 2.7.17

ansible25
lt 2.7.17

ansible24
lt 2.7.17

ansible23
lt 2.7.17

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1739
https://github.com/ansible/ansible/issues/67797
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FWDK3QUVBULS3Q3PQTGEKUQYPSNOU5M3/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QT27K5ZRGDPCH7GT3DRI3LO4IVDVQUB7/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U3IMV3XEIUXL6S4KPLYYM4TVJQ2VNEP2/
CVE-2020-1739