CVE-2017-7550 is a critical vulnerability in Ansible (versions 2.3.x before 2.3.3 and 2.4.x before 2.4.1) and Red Hat Enterprise Linux, where improper handling of parameters in the jenkins_plugin module could expose sensitive information from remote host logs. With a CVSS score of 9.8 (CRITICAL), this flaw allows unauthenticated remote attackers to achieve high confidentiality, integrity, and availability impacts with low attack complexity. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and the vulnerability shows minimal community discussion or media coverage, indicating it is not actively exploited or widely discussed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.0, < 2.3.3CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
>= 2.4.0, < 2.4.1CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.