Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16837

Опубликовано: 23 окт. 2018
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

The User module in Ansible leaks any data which is passed on as a parameter to ssh-keygen. This could lead to undesirable situations such as passphrase credentials being passed as a parameter for the ssh-keygen executable, showing those credentials in clear text form for every user which have access just to the process list.

Отчет

This issue affects the version of ansible as shipped with Red Hat Ceph Storage 3, as it contains the vulnerable code which leaks the data when ssh-keygen is invoked with any arguments.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2ansibleOut of support scope
Red Hat Ceph Storage 3ansibleAffected
Red Hat OpenStack Platform 10 (Newton)ansibleWill not fix
Red Hat Storage 3ansibleWill not fix
Red Hat Ansible Engine 2.5 for RHEL 7ansibleFixedRHSA-2018:346105.11.2018
Red Hat Ansible Engine 2.6 for RHEL 7ansibleFixedRHSA-2018:346005.11.2018
Red Hat Ansible Engine 2.7 for RHEL 7ansibleFixedRHSA-2018:346305.11.2018
Red Hat Ansible Engine 2 for RHEL 7ansibleFixedRHSA-2018:346205.11.2018
Red Hat OpenStack Platform 13.0 (Queens)ansibleFixedRHSA-2019:056414.03.2019
Red Hat OpenStack Platform 13.0 (Queens)openstack-ec2-apiFixedRHSA-2019:056414.03.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-214
https://bugzilla.redhat.com/show_bug.cgi?id=1640642Ansible: Information leak in "user" module

EPSS

Процентиль: 12%
0.0004
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

CVSS3: 7.8
nvd
больше 7 лет назад

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

CVSS3: 7.8
debian
больше 7 лет назад

Ansible "User" module leaks any data which is passed on as a parameter ...

CVSS3: 7.8
github
больше 3 лет назад

Ansible Leaks Data Passed to ssh-keygen

CVSS3: 7.8
fstec
больше 7 лет назад

Уязвимость модуля «User» системы управления конфигурациями Ansible, связанная с раскрытием данных, передаваемых в качестве параметров утилите ssh-keygen, позволяющая нарушителю получить несанкционированный доступ к конфиденциальной информации пользователя

EPSS

Процентиль: 12%
0.0004
Низкий

7.8 High

CVSS3