CVE-2018-16837
Severity CVSS v4.0:
Pending analysis
Type:
CWE-311
Missing Encryption of Sensitive Data
Publication date:
23/10/2018
Last modified:
03/10/2019
Description
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:redhat:ansible_engine:2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:ansible_engine:2.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:ansible_engine:2.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:ansible_engine:2.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:ansible_tower:3.3.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:suse:package_hub:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:suse:linux_enterprise:12.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.html
- http://www.securityfocus.com/bid/105700
- https://access.redhat.com/errata/RHSA-2018:3460
- https://access.redhat.com/errata/RHSA-2018:3461
- https://access.redhat.com/errata/RHSA-2018:3462
- https://access.redhat.com/errata/RHSA-2018:3463
- https://access.redhat.com/errata/RHSA-2018:3505
- https://access.redhat.com/security/cve/cve-2018-16837
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16837
- https://lists.debian.org/debian-lts-announce/2018/11/msg00012.html
- https://usn.ubuntu.com/4072-1/
- https://www.debian.org/security/2019/dsa-4396