Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hwrm-63v2-42g4

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

Ansible Leaks Data Passed to ssh-keygen

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.7.0a1, < 2.7.1

2.7.1

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.6.0a1, < 2.6.7

2.6.7

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 2.5.11

2.5.11

EPSS

Процентиль: 12%
0.0004
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

CVSS3: 7.8
redhat
больше 7 лет назад

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

CVSS3: 7.8
nvd
больше 7 лет назад

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

CVSS3: 7.8
debian
больше 7 лет назад

Ansible "User" module leaks any data which is passed on as a parameter ...

CVSS3: 7.8
fstec
больше 7 лет назад

Уязвимость модуля «User» системы управления конфигурациями Ansible, связанная с раскрытием данных, передаваемых в качестве параметров утилите ssh-keygen, позволяющая нарушителю получить несанкционированный доступ к конфиденциальной информации пользователя

EPSS

Процентиль: 12%
0.0004
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-311