git: 73c32ab8aecb - main - security/vuxml: Update Ansible's CVE-2021-3583

Mateusz Piotrowski 0mp at FreeBSD.org
Fri Jun 25 14:36:14 UTC 2021


The branch main has been updated by 0mp:

URL: https://cgit.FreeBSD.org/ports/commit/?id=73c32ab8aecb03224f406a79958ac5e3811790b4

commit 73c32ab8aecb03224f406a79958ac5e3811790b4
Author:     Mateusz Piotrowski <0mp at FreeBSD.org>
AuthorDate: 2021-06-25 14:27:15 +0000
Commit:     Mateusz Piotrowski <0mp at FreeBSD.org>
CommitDate: 2021-06-25 14:27:15 +0000

    security/vuxml: Update Ansible's CVE-2021-3583
    
    It turns out that it affects not only ansible-core, but also some other
    ports.
---
 security/vuxml/vuln-2021.xml | 19 ++++++++++++++++++-
 1 file changed, 18 insertions(+), 1 deletion(-)

diff --git a/security/vuxml/vuln-2021.xml b/security/vuxml/vuln-2021.xml
index f2ddc91ac36c..04107a08f274 100644
--- a/security/vuxml/vuln-2021.xml
+++ b/security/vuxml/vuln-2021.xml
@@ -1,5 +1,5 @@
   <vuln vid="4c9159ea-d4c9-11eb-aeee-8c164582fbac">
-    <topic>ansible-core -- Templating engine bug</topic>
+    <topic>Ansible -- Templating engine bug</topic>
     <affects>
       <package>
 	<name>py36-ansible-core</name>
@@ -8,6 +8,20 @@
 	<name>py39-ansible-core</name>
 	<range><lt>2.11.2</lt></range>
       </package>
+      <package>
+	<name>py36-ansible-base</name>
+	<name>py37-ansible-base</name>
+	<name>py38-ansible-base</name>
+	<name>py39-ansible-base</name>
+	<range><lt>2.10.11</lt></range>
+      </package>
+      <package>
+	<name>py36-ansible-base</name>
+	<name>py37-ansible-base</name>
+	<name>py38-ansible-base</name>
+	<name>py39-ansible-base</name>
+	<range><lt>2.9.23</lt></range>
+      </package>
     </affects>
     <description>
       <body xmlns="http://www.w3.org/1999/xhtml">
@@ -21,11 +35,14 @@
     <references>
       <cvename>CVE-2021-3583</cvename>
       <url>https://github.com/ansible/ansible/blob/stable-2.11/changelogs/CHANGELOG-v2.11.rst#security-fixes</url>
+      <url>https://github.com/ansible/ansible/blob/stable-2.10/changelogs/CHANGELOG-v2.10.rst#security-fixes</url>
       <url>https://github.com/ansible/ansible/pull/74960</url>
+      <url>https://groups.google.com/g/ansible-announce/c/tmIgD1DpZJg</url>
     </references>
     <dates>
       <discovery>2021-06-10</discovery>
       <entry>2021-06-24</entry>
+      <modified>2021-06-25</modified>
     </dates>
   </vuln>
 


More information about the dev-commits-ports-main mailing list