CVE-2016-8647

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
26/07/2018
Last modified:
26/01/2024

Description

An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* 2.2.1.0 (excluding)
cpe:2.3:a:redhat:virtualization:4.1:*:*:*:*:*:*:*