2020-06-11 19:24:01 +02:00
|
|
|
security_fixes:
|
2019-10-11 16:17:10 +02:00
|
|
|
- >
|
|
|
|
**security issue** - Convert CLI provided passwords to text initially, to
|
|
|
|
prevent unsafe context being lost when converting from bytes->text during
|
|
|
|
post processing of PlayContext. This prevents CLI provided passwords from
|
|
|
|
being incorrectly templated (CVE-2019-14856)
|
|
|
|
- >
|
|
|
|
**security issue** - Update ``AnsibleUnsafeText`` and ``AnsibleUnsafeBytes``
|
|
|
|
to maintain unsafe context by overriding ``.encode`` and ``.decode``. This
|
|
|
|
prevents future issues with ``to_text``, ``to_bytes``, or ``to_native``
|
|
|
|
removing the unsafe wrapper when converting between string types
|
|
|
|
(CVE-2019-14856)
|