Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v735-2pp6-h86r

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.7
CVSS3: 4.4

Описание

Ansible Logs Passwords If PowerShell ScriptBlock is Enabled

Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.7.0a1, < 2.7.3

2.7.3

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 2.5.12

2.5.12

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.6.0a1, < 2.6.9

2.6.9

EPSS

Процентиль: 27%
0.00096
Низкий

6.7 Medium

CVSS4

4.4 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 4.2
redhat
около 7 лет назад

Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.

CVSS3: 4.2
nvd
около 7 лет назад

Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.

CVSS3: 4.2
debian
около 7 лет назад

Execution of Ansible playbooks on Windows platforms with PowerShell Sc ...

suse-cvrf
больше 6 лет назад

Security update for ansible

suse-cvrf
почти 7 лет назад

Security update for ansible

EPSS

Процентиль: 27%
0.00096
Низкий

6.7 Medium

CVSS4

4.4 Medium

CVSS3

Дефекты

CWE-532