Skip to content

Conversation

awsactran
Copy link
Contributor

According to the maintainers/clarification ansible-collections/community.aws#237 (comment) .

The issue was fixed in version 1.2.1. Hence, I am updating the YAML to add fixed version accordingly.

@awsactran
Copy link
Contributor Author

@oliverchang Apologies for tagging you here. But it seems that this PR was hanging for 3 weeks now so wondering if you can help reviewing and merging the change.

TIA

@di
Copy link
Member

di commented Aug 19, 2025

https://access.redhat.com/security/cve/CVE-2020-25635 says:

Ansible collection aws_ssm connection community plugin 1.2.1 and previous versions until 1.0.0 when it was introduced to this plugin, are the versions affected by this flaw.

So it seems like this was actually introduced in 1.0.0 and fixed in 1.2.2?

Furthermore, this vulnerability seems to be in the https://github.com/ansible-collections/community.aws/ project, (where version 1.2.1 was created in August 2023) and not the https://pypi.org/project/ansible/ project, where version 1.2.1 was created in July 2013.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants