Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hwrm-63v2-42g4

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

Ansible Leaks Data Passed to ssh-keygen

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.7.0a1, < 2.7.1

2.7.1

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.6.0a1, < 2.6.7

2.6.7

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 2.5.11

2.5.11

EPSS

Процентиль: 29%
0.00357
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

CVSS3: 7.8
redhat
почти 8 лет назад

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

CVSS3: 7.8
nvd
почти 8 лет назад

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

CVSS3: 7.8
debian
почти 8 лет назад

Ansible "User" module leaks any data which is passed on as a parameter ...

CVSS3: 7.8
fstec
почти 8 лет назад

Уязвимость модуля «User» системы управления конфигурациями Ansible, связанная с раскрытием данных, передаваемых в качестве параметров утилите ssh-keygen, позволяющая нарушителю получить несанкционированный доступ к конфиденциальной информации пользователя

EPSS

Процентиль: 29%
0.00357
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-311