Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.
Weaknesses in this category are related to errors in the management of cryptographic keys.
Link | Tags |
---|---|
https://www.ansible.com/security | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=980821 | issue tracking |
https://github.com/ansible/ansible/issues/857 | issue tracking third party advisory |
http://www.openwall.com/lists/oss-security/2013/07/01/2 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2013/07/02/6 | third party advisory mailing list |